Methodology
Windows Exploit Suggester
wesng (Recommended)
systeminfo output from victim:
Watson (.NET — Run on Target)
Sherlock (PowerShell — Deprecated but Works)
Check Installed Patches
Common Kernel Exploits
MS16-032 — Secondary Logon (Windows 7/8/10, Server 2008/2012)
KB3139914
MS15-051 — Win32k (Windows 7, Server 2008)
KB3045171
MS14-058 — TrackPopupMenu (Windows 7, Server 2008)
KB3000061
CVE-2021-1675 / CVE-2021-34527 — PrintNightmare
See dedicated PrintNightmare page.CVE-2021-36934 — HiveNightmare / SeriousSAM
SAM/SYSTEM readable by non-admin due to shadow copy ACL. Check:BUILTIN\Users has read access: