
Just popped Arctic on HTB Old ColdFusion 8 → CVE-2009-2265 RCE → shell as arctic\tolis. I upgraded to Meterpreter, migrated x86→x64, then used MS16-075 (Juicy Potato/DCOM NTLM reflection) to escalate to SYSTEM. https://blog.charleskoome.com/posts/arctic-hackthebox-writeup/ #HTB #InfoSec #Pentesting #Windows
Post summary
The writeup demonstrates a successful exploitation of ColdFusion 8 CVE‑2009‑2265 RCE, achieving a shell and escalating privileges to SYSTEM using the Juicy Potato exploit.

