Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

2026-06-20T19:24:10Z2e4de3bfe674c19ad022129aadfa428a7ac5681ac6c87050326cf2a8388839ce
CVE-2026-41679MCP serverNTLM relayPaperclipPaperclip AIRCES4U2ProxyShadow CredentialsVS Code extensionXerte Online Toolkitsexploitmetasploitpersistencepost-exploitationprivilege escalation

What happened

Rapid7 weekly Metasploit update adds five new modules and enhancements. Notably, an unauthenticated full remote code execution exploit for Paperclip AI (CVE-2026-41679) enables RCE via a six-API-call chain against network-accessible Paperclip instances with default configuration. A new post‑exploitation module windows/local/ntlm_relay_2_self coerces the local machine account to authenticate (via OpenEncryptedFileRaw/WebDAV), relays NTLM to a Domain Controller LDAP service, writes Shadow Credentials, and uses S4U2Proxy to obtain a Kerberos service ticket as Administrator to achieve SYSTEM (PsEx

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
2e4de3bfe674c19ad022129aadfa428a7ac5681ac6c87050326cf2a8388839ce
Enrichment time
2026-06-20T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.