References https://payloads.online/archivers/2020-03-21/1/ https://blog.csdn.net/qq_40012781/article/details/125576708 https://cloud.tencent.com/developer/article/1662337 https://rivers.chaitin.cn/blog/cqmg4e90lnec5jjug7tg https://www.cnblogs.com/kqdssheng/p/18785725 https://pingmaoer.github.io/2020/06/11/%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E5%88%86%E6%9E%90%E5%8F%8A%E9%98%B2%E5%BE%A1%E4%B8%80/ https://developer.aliyun.com/article/1227455 https://zhuanlan.zhihu.com/p/572730623 https://www.4hou.com/posts/7VxQ https://www.anquanke.com/post/id/241804 https://ryze-t.com/2022/01/18/Windows-%E6%8F%90%E6%9D%83%E6%B1%87%E6%80%BB/ https://github.com/nickvourd/Windows-Local-Privilege-Escalation-Cookbook/blob/master/Notes/WeakRegistryPermissions.md https://amanisher.medium.com/windows-privilege-escalation-via-registry-d59ddfddcbde https://blog.securelayer7.net/cve-2026-24291-regpwn-windows-privilege-escalation/ https://juggernaut-sec.com/weak-registry-key-permissions/ https://cve.imfht.com/detail/CVE-2015-0073 https://avd.aliyun.com/detail?id=AVD-2024-43641 https://support.microsoft.com/zh-cn/topic/ms16-124-windows-%E6%B3%A8%E5%86%8C%E8%A1%A8%E5%AE%89%E5%85%A8%E6%9B%B4%E6%96%B0%E8%AF%B4%E6%98%8E-2016-%E5%B9%B4-10-%E6%9C%88-11-%E6%97%A5-bf65aef9-75c9-b79f-2390-940442afb2bd https://cloud.tencent.com/developer/article/2579116
Related VulnerabilitiesWindows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File ExposureWindows PolicyConfiguration 计划任务特权提升漏洞(CVE-2025-60710)Windows 11 PolicyConfiguration 计划任务特权提升漏洞(CVE-2025-60710)Windows 11 RAiLaunchAdminProcess 管理员保护特权提升漏洞(CVE-2025-62522)Vite开发服务器Windows环境下文件泄露漏洞(CVE-2025-41246) VMware Tools for Windows授权不当漏洞Windows NTLMv2-SSP Hash信息泄露漏洞(CVE-2025-50154)(CVE-2025-26513)SAN Host Utilities for Windows 8.0前版本安装程序本地权限提升漏洞(CVE-2025-8088) WinRAR Windows版本路径遍历漏洞可导致任意代码执行PoCCVE-2015-1635: Microsoft Windows 'HTTP.sys' - Remote Code Execution