Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
2026-06-23T07:23:45Z•c3633b5b8cb2cf923f0538b0144c7addf86ad8ab13cc520f08fc058ec4c0346f
CVE-2026-41679DLL sideloadingDonut shellcodeDropping ElephantKerberos tracingMCP serverNTLM relayPaperclip AIS4U2ProxyXerte Online Toolkitsdetection guidanceexploitmalwaremetasploitmsfconsoleprivilege escalationshadow credentialsunauthenticated RCE
What happened
Rapid7 weekly roundup covering five new Metasploit modules and multiple research posts. Notable items: an unauthenticated end-to-end RCE exploit for Paperclip AI (linux/http/paperclipai_unauth_rce_cve_2026_41679) that achieves full remote code execution via a six-API-call chain; a post‑exploitation Windows module (windows/local/ntlm_relay_2_self) that coerces the local machine account into NTLM authentication, relays it to a Domain Controller’s LDAP to write shadow credentials and obtain an Administrator Kerberos ticket via S4U2Proxy for SYSTEM escalation; new MCP server plugin to integrate AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- c3633b5b8cb2cf923f0538b0144c7addf86ad8ab13cc520f08fc058ec4c0346f
- Enrichment time
- 2026-06-23T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.