Overview
- Type Machines
- Direct https://app.hackthebox.com/machines/DanglingTree
- OS Windows
- Severity Medium
- Creator EmSec
- Release date 2026 Aug 9 (JST)
DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.
