Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
2026-06-20T07:23:53Z•78cc57673c50743676275d454b0c59ff2b4b35e8e625b855079bd20ed5967370
AI integrationCVE-2026-41679DLL side-loadingDonut shellcodeDropping ElephantFondue.exeKerberosLDAP relayMCP serverNIS2NTLM relayOpenEncryptedFileRawPaperclipPsExecS4U2ProxyWebDAVXerte arbitrary file uploadexploitin-memory RATmalwaremetasploitremote code executionunauthenticated RCEvulnerability managementwindows local privilege escalation
What happened
Rapid7 blog roundup: Metasploit received five new modules including an unauthenticated full RCE against Paperclip AI (CVE-2026-41679) achievable with a six‑API‑call chain; a Windows local privilege escalation module (windows/local/ntlm_relay_2_self) that coerces the machine account via OpenEncryptedFileRaw (WebDAV), relays NTLM to a Domain Controller's LDAP, writes Shadow Credentials and obtains an Administrator Kerberos ticket via S4U2Proxy to achieve SYSTEM; an MCP server plugin to let AI tools assist operators inside msfconsole; and other exploit modules (e.g., Xerte arbitrary file upload).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 78cc57673c50743676275d454b0c59ff2b4b35e8e625b855079bd20ed5967370
- Enrichment time
- 2026-06-20T07:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.