Skip to content

Commit 5ac6c91

Browse files
authored
Service DACL false positive
1 parent 5e2200b commit 5ac6c91

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

Privesc/PowerUp.ps1

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1404,7 +1404,7 @@ function Test-ServiceDaclPermission {
14041404
else {
14051405
ForEach($TargetPermission in $TargetPermissions) {
14061406
# check permissions || style
1407-
if (($ServiceDacl.AccessRights -band $AccessMask[$TargetPermission]) -eq $AccessMask[$TargetPermission]) {
1407+
if (($ServiceDacl.AceType -eq 'AccessAllowed') -and ($ServiceDacl.AccessRights -band $AccessMask[$TargetPermission]) -eq $AccessMask[$TargetPermission]) {
14081408
Write-Verbose "Current user has '$TargetPermission' for $IndividualService"
14091409
$TargetService
14101410
break

0 commit comments

Comments
 (0)