HiveNightmare
CVE-2021–36934 allows you to retrieve all registry hives (SAM,SECURITY,SYSTEM) in Windows 10 and 11 as a non-administrator user.
Exploitation
Check for the vulnerability using icacls
Then exploit the CVE by requesting the shadowcopies on the filesystem and reading the hives from it.
List shadow copies available
Extract account from SAM databases
Extract secrets from SECURITY
Last updated