> For the complete documentation index, see [llms.txt](https://hackzzz.gitbook.io/welcome/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackzzz.gitbook.io/welcome/everything-about-and-notes/windows-and-active-directory/windows-privilege-escalation/abusing-the-golden-privileges.md).

# Abusing the Golden Privileges

**Permissions:&#x20;**<mark style="color:green;">**User**</mark>

<figure><img src="https://1589701199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi9hCCmXtAKNvbIKRqULt%2Fuploads%2FoAw6042lomhwx7PzttZe%2Fseimpersonate1.png?alt=media&amp;token=4f94f7fc-109b-45f3-a13f-46ed3b21bd23" alt=""><figcaption></figcaption></figure>

Let's say that we have enable `SeImpersonatePrivilege` or `SeAssignPrimaryToken` privilege in the machine, we can use **juicypotato** binary to try to impersonate commands as **administrator** user, If the user has `SeImpersonate` or `SeAssignPrimaryToken` privileges then you are **SYSTEM**.

{% embed url="<https://github.com/ohpe/juicy-potato>" %}

<figure><img src="https://1589701199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi9hCCmXtAKNvbIKRqULt%2Fuploads%2FfPxTHPQ5X1iY9gmnYQra%2Fjuicypotato_add_user.png?alt=media&amp;token=9044e93c-311f-4282-8da1-41ca7fabe955" alt=""><figcaption></figcaption></figure>

Here you can see how I create a user using the **juicypotato** exploit.

{% hint style="info" %}
**Use a respective CLSID to the windows version** in case the exploit doesn't work and try again.
{% endhint %}
