daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

local-ntlm-reflection-via-smb-arbitrary-port.md (7080B)


      1 ---
      2 title: "Local NTLM Reflection via SMB Arbitrary Port"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Local NTLM Reflection via SMB Arbitrary Port
     14 
     15 Recent Windows builds introduced **SMB client support for alternative TCP ports**. That feature can be abused to turn **local NTLM authentication** into a **SYSTEM local privilege escalation** when the attacker can:<sup>[[1]](#references)</sup>
     16 
     17 1. Open an SMB connection to an attacker-controlled listener on a **non-445 port**
     18 2. Keep that TCP connection alive
     19 3. Coerce a **privileged local client** to access the **same SMB share path**
     20 4. Relay the resulting **local NTLM authentication** back to the machine's real SMB service
     21 
     22 This is the primitive behind **CVE-2026-24294**, patched in **March 2026**.<sup>[[1]](#references)[[4]](#references)</sup>
     23 
     24 ## Why it works
     25 
     26 The older CMTI / serialized-SPN reflection trick is covered here:
     27 
     28 [Readme](/hacktricks/windows-hardening/ntlm/overview)
     29 
     30 This newer variant does **not** need a marshalled hostname. Instead it abuses two SMB client behaviours:<sup>[[1]](#references)</sup>
     31 
     32 - **Alternative port support** on **Windows 11 24H2** and **Windows Server 2025**, exposed to users with `net use \\host\share /tcpport:<port>`
     33 - **SMB connection reuse / multiplexing**, where multiple authenticated sessions can ride the same TCP connection
     34 
     35 That means a low-privileged user can first create a TCP connection from the SMB client to an attacker SMB server on a high port, then coerce a privileged service to access the **exact same UNC path**. If Windows decides to reuse the existing TCP connection, the privileged NTLM exchange is sent over the attacker-controlled transport and can be relayed to the local SMB server.<sup>[[1]](#references)</sup>
     36 
     37 ## Preconditions
     38 
     39 - Target supports SMB alternative ports:<sup>[[2]](#references)</sup>
     40   - **Windows 11 24H2** or later
     41   - **Windows Server 2025** or later
     42 - The attacker can run a local or remote SMB server on a chosen high port
     43 - The attacker can coerce a privileged service to access a UNC path
     44 - The privileged authentication must be **NTLM local authentication**
     45 - The target must be relayable:<sup>[[1]](#references)</sup>
     46   - Synacktiv reported it worked by default on **Windows Server 2025**
     47   - Their chain did **not** work on **Windows 11 24H2** because outbound SMB signing is enforced there by default
     48 
     49 ## Userland and internals
     50 
     51 From the command line the feature looks simple:
     52 
     53 ```batch
     54 net use \\192.168.56.3\share /tcpport:12345
     55 ```
     56 
     57 Programmatically, the client uses `WNetAddConnection4W` with undocumented `lpUseOptions` data. The relevant option is `TraP` (transport parameters), which eventually reaches the kernel SMB client through an FSCTL and is parsed by `mrxsmb`.<sup>[[1]](#references)[[3]](#references)</sup>
     58 
     59 Important practical notes:<sup>[[1]](#references)</sup>
     60 
     61 - **UNC syntax still has no port field**
     62 - **`net use` is per-logon-session**
     63 - The bypass still works because **the TCP connection and the SMB session are separate objects**
     64 - Reusing the **same share path** is mandatory if the exploit depends on the SMB client reusing the previously created TCP connection
     65 
     66 ## Exploitation flow
     67 
     68 ### 1. Create the attacker-controlled SMB transport
     69 
     70 Run an SMB server on a high port and make Windows connect to it:
     71 
     72 ```batch
     73 net use \\192.168.56.3\share /tcpport:12345
     74 ```
     75 
     76 The server can accept any credential pair you control, for example `user:user`. The goal of this step is not privilege escalation yet, only to make the Windows SMB client open and keep a reusable TCP connection to your listener.<sup>[[1]](#references)</sup>
     77 
     78 ### 2. Coerce a privileged service to the same UNC path
     79 
     80 Use a coercion primitive such as **PetitPotam** against the **same** `\\192.168.56.3\share` path. If the coerced client is privileged and the target name is local (`localhost` or a local IP/host), Windows performs **NTLM local authentication**.
     81 
     82 Because the TCP connection is reused, that privileged NTLM exchange travels to the attacker SMB service instead of directly to the real local SMB server.<sup>[[1]](#references)</sup>
     83 
     84 ### 3. Relay the privileged authentication back to local SMB
     85 
     86 The attacker-controlled SMB service forwards the privileged NTLM exchange to `ntlmrelayx.py`, which relays it to the machine's real SMB listener and obtains a session as `NT AUTHORITY\SYSTEM`.<sup>[[1]](#references)</sup>
     87 
     88 Typical tooling from the public writeup:<sup>[[1]](#references)</sup>
     89 
     90 - `smbserver.py` on a custom port to receive the privileged auth over the reused TCP connection
     91 - `ntlmrelayx.py` to relay the captured NTLM to local SMB
     92 - `PetitPotam.exe` or another coercion primitive to force the privileged authentication
     93 
     94 ## Operator notes
     95 
     96 - This is a **local privilege escalation** technique, not a generic remote relay trick<sup>[[1]](#references)</sup>
     97 - The attacker-controlled SMB service must handle the privileged authentication on the **same TCP connection** originally used for the share mount<sup>[[1]](#references)</sup>
     98 - If the coerced access hits a **different share path**, Windows may establish a different connection and the chain breaks<sup>[[1]](#references)</sup>
     99 - SMB signing requirements can kill the relay even when the arbitrary-port step works<sup>[[1]](#references)</sup>
    100 - If you only have Kerberos material or cannot force local NTLM, this exact variant is not enough<sup>[[1]](#references)</sup>
    101 
    102 ## Detection and hardening
    103 
    104 - Patch **CVE-2026-24294** from **March 2026 Patch Tuesday**<sup>[[4]](#references)</sup>
    105 - Watch for `net use` or `New-SmbMapping` using **non-default SMB ports**<sup>[[1]](#references)</sup>
    106 - Alert on unusual outbound SMB from workstations or servers to **high TCP ports**<sup>[[1]](#references)</sup>
    107 - Review coercion opportunities such as **EFSRPC / PetitPotam-style** triggers<sup>[[1]](#references)</sup>
    108 - Enforce SMB signing where possible; Synacktiv specifically notes this blocked their relay on Windows 11 24H2<sup>[[1]](#references)</sup>
    109 
    110 ## References
    111 
    112 - [1] [Synacktiv - Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1](https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1.html)
    113 - [2] [Microsoft Learn - Configure alternative SMB ports for Windows Server 2025](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-ports)
    114 - [3] [Microsoft Learn - WNetAddConnection4W](https://learn.microsoft.com/en-us/windows/win32/api/winnetwk/nf-winnetwk-wnetaddconnection4w)
    115 - [4] [MSRC - CVE-2026-24294](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24294)