Impacket-GoldenPac
NEW Privilege EscalationExecutionLateral Movement LinuxActiveDirectoryWindows
Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments. Command Reference: Domain: test.local Username: john Password: password123 Domain Controller host: dc.test.local