In this author's experience, Windows-based web servers have a considerable market share in business environments, and for internal web applications they may be more than 60% in a typical organization, adding to this the clear dominance of Microsoft SQL Server in the database market. This means that as penetration testers, we will surely face the situation where we manage to get command execution on a Windows server and need to gain administrative access in order to further exploit the network.
In this recipe, we will start from a limited web-shell on a Windows server and use publicly available exploits to gain system access, the highest local privilege level in Windows.