Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

2026-06-23T07:23:45Zc3633b5b8cb2cf923f0538b0144c7addf86ad8ab13cc520f08fc058ec4c0346f
CVE-2026-41679DLL sideloadingDonut shellcodeDropping ElephantKerberos tracingMCP serverNTLM relayPaperclip AIS4U2ProxyXerte Online Toolkitsdetection guidanceexploitmalwaremetasploitmsfconsoleprivilege escalationshadow credentialsunauthenticated RCE

What happened

Rapid7 weekly roundup covering five new Metasploit modules and multiple research posts. Notable items: an unauthenticated end-to-end RCE exploit for Paperclip AI (linux/http/paperclipai_unauth_rce_cve_2026_41679) that achieves full remote code execution via a six-API-call chain; a post‑exploitation Windows module (windows/local/ntlm_relay_2_self) that coerces the local machine account into NTLM authentication, relays it to a Domain Controller’s LDAP to write shadow credentials and obtain an Administrator Kerberos ticket via S4U2Proxy for SYSTEM escalation; new MCP server plugin to integrate AI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
c3633b5b8cb2cf923f0538b0144c7addf86ad8ab13cc520f08fc058ec4c0346f
Enrichment time
2026-06-23T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.