Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
2026-06-20T19:24:10Z•2e4de3bfe674c19ad022129aadfa428a7ac5681ac6c87050326cf2a8388839ce
CVE-2026-41679MCP serverNTLM relayPaperclipPaperclip AIRCES4U2ProxyShadow CredentialsVS Code extensionXerte Online Toolkitsexploitmetasploitpersistencepost-exploitationprivilege escalation
What happened
Rapid7 weekly Metasploit update adds five new modules and enhancements. Notably, an unauthenticated full remote code execution exploit for Paperclip AI (CVE-2026-41679) enables RCE via a six-API-call chain against network-accessible Paperclip instances with default configuration. A new post‑exploitation module windows/local/ntlm_relay_2_self coerces the local machine account to authenticate (via OpenEncryptedFileRaw/WebDAV), relays NTLM to a Domain Controller LDAP service, writes Shadow Credentials, and uses S4U2Proxy to obtain a Kerberos service ticket as Administrator to achieve SYSTEM (PsEx
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 2e4de3bfe674c19ad022129aadfa428a7ac5681ac6c87050326cf2a8388839ce
- Enrichment time
- 2026-06-20T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.