The Meterpreter session provided further access to the machine.

By running the executable with a specific argument:

🧗 User access was straightforward once you found the config file, but Root was a different story. Had to leverage a misconfigured [SUID binary / Cron job / Docker group] to break out of the shell.

Files and directories within the share were enumerated. A suspicious file, privesc.exe , was discovered.