Members of the DNSAdmins group are able to modify the DNS service, causing it to load an arbitrary DLL. This DLL runs as SYSTEM, allowing for SYSTEM level code execution on the DNS server, which is usually a DC.
🔍 Discovery
This requires a user in the DNSAdmins group.
📌 Exploitation
First, generate a malicious DLL for the DNS server to execute:
Next on the DNS server, use dnscmd.exe to register and run the DLL: