Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

2026-06-20T07:23:53Z78cc57673c50743676275d454b0c59ff2b4b35e8e625b855079bd20ed5967370
AI integrationCVE-2026-41679DLL side-loadingDonut shellcodeDropping ElephantFondue.exeKerberosLDAP relayMCP serverNIS2NTLM relayOpenEncryptedFileRawPaperclipPsExecS4U2ProxyWebDAVXerte arbitrary file uploadexploitin-memory RATmalwaremetasploitremote code executionunauthenticated RCEvulnerability managementwindows local privilege escalation

What happened

Rapid7 blog roundup: Metasploit received five new modules including an unauthenticated full RCE against Paperclip AI (CVE-2026-41679) achievable with a six‑API‑call chain; a Windows local privilege escalation module (windows/local/ntlm_relay_2_self) that coerces the machine account via OpenEncryptedFileRaw (WebDAV), relays NTLM to a Domain Controller's LDAP, writes Shadow Credentials and obtains an Administrator Kerberos ticket via S4U2Proxy to achieve SYSTEM; an MCP server plugin to let AI tools assist operators inside msfconsole; and other exploit modules (e.g., Xerte arbitrary file upload).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
78cc57673c50743676275d454b0c59ff2b4b35e8e625b855079bd20ed5967370
Enrichment time
2026-06-20T07:23:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.