Windows Privilege Escalation with SeImpersonatePrivilege, and SeAssignPrimaryTokenPrivilege

Photo by Hans Isaacson on Unsplash
Today, I am going to talk about a Windows privilege escalation tool called Juicy Potato. In the past, I used it on Hack The box older machines: Bounty, Jeeves, and Conceal to escalate my privileges from a local user to an Administrator.
Juicy Potato is a local privilege escalation tool created by Andrea Pierini and Giuseppe Trotta to exploit Windows service accounts’ impersonation privileges.
The tool takes advantage of the SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege if enabled on the machine to elevate the local privileges to System. Normally, these privileges are assigned to service users, admins, and local systems — high integrity elevated users.