Windows UAC Bypass Techniques
Bypassing User Account Control (UAC) by Spoofing Trusted Directories
Introduction
What is UAC?
UAC Operation
UAC Bypass: The Directory Spoofing Technique
Requirement 1: Auto-Elevation of Privileges
Requirement 2: Signature Verification
Requirement 3: Execution from a Trusted Directory
Bypass Strategy
Bypass Implementation
Scheduled Tasks Bypass
Environment Variable Manipulation
Event Viewer Bypass
Mock Folders Bypass
Token Impersonation
Bypass Using SilentCleanup
UAC Bypass via ICMLuaUtil Elevated COM Interface
UAC Bypass via ComputerDefaults Execution Hijack
UAC Bypass via Control Panel Execution Hijack
UAC Bypass via DiskCleanup Scheduled Task Hijack
UAC Bypass via FodHelper Execution Hijack
UAC Bypass Attempt via Windows Directory Masquerading
Metasploit UAC Bypass
Silent Process Exit Bypass
App Paths Bypass
Mocking Trusted Directories
Conclusion
PreviousPrivilege EscalationNextObtaining SYSTEM privilege via a vulnerable driver using a Userland program
Last updated