local-ntlm-reflection-via-smb-arbitrary-port.md (7080B)
1 --- 2 title: "Local NTLM Reflection via SMB Arbitrary Port" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Local NTLM Reflection via SMB Arbitrary Port 14 15 Recent Windows builds introduced **SMB client support for alternative TCP ports**. That feature can be abused to turn **local NTLM authentication** into a **SYSTEM local privilege escalation** when the attacker can:<sup>[[1]](#references)</sup> 16 17 1. Open an SMB connection to an attacker-controlled listener on a **non-445 port** 18 2. Keep that TCP connection alive 19 3. Coerce a **privileged local client** to access the **same SMB share path** 20 4. Relay the resulting **local NTLM authentication** back to the machine's real SMB service 21 22 This is the primitive behind **CVE-2026-24294**, patched in **March 2026**.<sup>[[1]](#references)[[4]](#references)</sup> 23 24 ## Why it works 25 26 The older CMTI / serialized-SPN reflection trick is covered here: 27 28 [Readme](/hacktricks/windows-hardening/ntlm/overview) 29 30 This newer variant does **not** need a marshalled hostname. Instead it abuses two SMB client behaviours:<sup>[[1]](#references)</sup> 31 32 - **Alternative port support** on **Windows 11 24H2** and **Windows Server 2025**, exposed to users with `net use \\host\share /tcpport:<port>` 33 - **SMB connection reuse / multiplexing**, where multiple authenticated sessions can ride the same TCP connection 34 35 That means a low-privileged user can first create a TCP connection from the SMB client to an attacker SMB server on a high port, then coerce a privileged service to access the **exact same UNC path**. If Windows decides to reuse the existing TCP connection, the privileged NTLM exchange is sent over the attacker-controlled transport and can be relayed to the local SMB server.<sup>[[1]](#references)</sup> 36 37 ## Preconditions 38 39 - Target supports SMB alternative ports:<sup>[[2]](#references)</sup> 40 - **Windows 11 24H2** or later 41 - **Windows Server 2025** or later 42 - The attacker can run a local or remote SMB server on a chosen high port 43 - The attacker can coerce a privileged service to access a UNC path 44 - The privileged authentication must be **NTLM local authentication** 45 - The target must be relayable:<sup>[[1]](#references)</sup> 46 - Synacktiv reported it worked by default on **Windows Server 2025** 47 - Their chain did **not** work on **Windows 11 24H2** because outbound SMB signing is enforced there by default 48 49 ## Userland and internals 50 51 From the command line the feature looks simple: 52 53 ```batch 54 net use \\192.168.56.3\share /tcpport:12345 55 ``` 56 57 Programmatically, the client uses `WNetAddConnection4W` with undocumented `lpUseOptions` data. The relevant option is `TraP` (transport parameters), which eventually reaches the kernel SMB client through an FSCTL and is parsed by `mrxsmb`.<sup>[[1]](#references)[[3]](#references)</sup> 58 59 Important practical notes:<sup>[[1]](#references)</sup> 60 61 - **UNC syntax still has no port field** 62 - **`net use` is per-logon-session** 63 - The bypass still works because **the TCP connection and the SMB session are separate objects** 64 - Reusing the **same share path** is mandatory if the exploit depends on the SMB client reusing the previously created TCP connection 65 66 ## Exploitation flow 67 68 ### 1. Create the attacker-controlled SMB transport 69 70 Run an SMB server on a high port and make Windows connect to it: 71 72 ```batch 73 net use \\192.168.56.3\share /tcpport:12345 74 ``` 75 76 The server can accept any credential pair you control, for example `user:user`. The goal of this step is not privilege escalation yet, only to make the Windows SMB client open and keep a reusable TCP connection to your listener.<sup>[[1]](#references)</sup> 77 78 ### 2. Coerce a privileged service to the same UNC path 79 80 Use a coercion primitive such as **PetitPotam** against the **same** `\\192.168.56.3\share` path. If the coerced client is privileged and the target name is local (`localhost` or a local IP/host), Windows performs **NTLM local authentication**. 81 82 Because the TCP connection is reused, that privileged NTLM exchange travels to the attacker SMB service instead of directly to the real local SMB server.<sup>[[1]](#references)</sup> 83 84 ### 3. Relay the privileged authentication back to local SMB 85 86 The attacker-controlled SMB service forwards the privileged NTLM exchange to `ntlmrelayx.py`, which relays it to the machine's real SMB listener and obtains a session as `NT AUTHORITY\SYSTEM`.<sup>[[1]](#references)</sup> 87 88 Typical tooling from the public writeup:<sup>[[1]](#references)</sup> 89 90 - `smbserver.py` on a custom port to receive the privileged auth over the reused TCP connection 91 - `ntlmrelayx.py` to relay the captured NTLM to local SMB 92 - `PetitPotam.exe` or another coercion primitive to force the privileged authentication 93 94 ## Operator notes 95 96 - This is a **local privilege escalation** technique, not a generic remote relay trick<sup>[[1]](#references)</sup> 97 - The attacker-controlled SMB service must handle the privileged authentication on the **same TCP connection** originally used for the share mount<sup>[[1]](#references)</sup> 98 - If the coerced access hits a **different share path**, Windows may establish a different connection and the chain breaks<sup>[[1]](#references)</sup> 99 - SMB signing requirements can kill the relay even when the arbitrary-port step works<sup>[[1]](#references)</sup> 100 - If you only have Kerberos material or cannot force local NTLM, this exact variant is not enough<sup>[[1]](#references)</sup> 101 102 ## Detection and hardening 103 104 - Patch **CVE-2026-24294** from **March 2026 Patch Tuesday**<sup>[[4]](#references)</sup> 105 - Watch for `net use` or `New-SmbMapping` using **non-default SMB ports**<sup>[[1]](#references)</sup> 106 - Alert on unusual outbound SMB from workstations or servers to **high TCP ports**<sup>[[1]](#references)</sup> 107 - Review coercion opportunities such as **EFSRPC / PetitPotam-style** triggers<sup>[[1]](#references)</sup> 108 - Enforce SMB signing where possible; Synacktiv specifically notes this blocked their relay on Windows 11 24H2<sup>[[1]](#references)</sup> 109 110 ## References 111 112 - [1] [Synacktiv - Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1](https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1.html) 113 - [2] [Microsoft Learn - Configure alternative SMB ports for Windows Server 2025](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-ports) 114 - [3] [Microsoft Learn - WNetAddConnection4W](https://learn.microsoft.com/en-us/windows/win32/api/winnetwk/nf-winnetwk-wnetaddconnection4w) 115 - [4] [MSRC - CVE-2026-24294](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24294)