daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

secure-desktop-accessibility-registry-propagation-regpwn.md (5236B)


      1 ---
      2 title: "Secure Desktop Accessibility Registry Propagation LPE (RegPwn)"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Secure Desktop Accessibility Registry Propagation LPE (RegPwn)
     14 
     15 ## Overview
     16 
     17 Windows Accessibility features persist user configuration under HKCU and propagate it into per-session HKLM locations. During a **Secure Desktop** transition (lock screen or UAC prompt), **SYSTEM** components re-copy these values. If the **per-session HKLM key is writable by the user**, it becomes a privileged write choke point that can be redirected with **registry symbolic links**, yielding an **arbitrary SYSTEM registry write**.<sup>[[1]](#references)</sup>
     18 
     19 The RegPwn technique abuses that propagation chain with a small race window stabilized via an **opportunistic lock (oplock)** on a file used by `osk.exe`.<sup>[[1]](#references)</sup>
     20 
     21 ## Registry Propagation Chain (Accessibility -> Secure Desktop)
     22 
     23 Example feature: **On-Screen Keyboard** (`osk`). The relevant locations are:
     24 
     25 - **System-wide feature list**:
     26   - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs`
     27 - **Per-user configuration (user-writable)**:
     28   - `HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk`
     29 - **Per-session HKLM config (created by `winlogon.exe`, user-writable)**:
     30   - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<session id>\ATConfig\osk`
     31 - **Secure desktop/default user hive (SYSTEM context)**:
     32   - `HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk`
     33 
     34 Propagation during a secure desktop transition (simplified):
     35 
     36 1. **User `atbroker.exe`** copies `HKCU\...\ATConfig\osk` to `HKLM\...\Session<session id>\ATConfig\osk`.
     37 2. **SYSTEM `atbroker.exe`** copies `HKLM\...\Session<session id>\ATConfig\osk` to `HKU\.DEFAULT\...\ATConfig\osk`.
     38 3. **SYSTEM `osk.exe`** copies `HKU\.DEFAULT\...\ATConfig\osk` back to `HKLM\...\Session<session id>\ATConfig\osk`.
     39 
     40 If the session HKLM subtree is writable by the user, step 2/3 provide a SYSTEM write through a location the user can replace.<sup>[[1]](#references)</sup>
     41 
     42 ## Primitive: Arbitrary SYSTEM Registry Write via Registry Links
     43 
     44 Replace the user-writable per-session key with a **registry symbolic link** that points to an attacker-chosen destination. When the SYSTEM copy occurs, it follows the link and writes attacker-controlled values into the arbitrary target key.
     45 
     46 Key idea:
     47 
     48 - Victim write target (user-writable):
     49   - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<session id>\ATConfig\osk`
     50 - Attacker replaces that key with a **registry link** to any other key.
     51 - SYSTEM performs the copy and writes into the attacker-chosen key with SYSTEM permissions.
     52 
     53 This yields an **arbitrary SYSTEM registry write** primitive.<sup>[[1]](#references)</sup>
     54 
     55 ## Winning the Race Window with Oplocks
     56 
     57 There is a short timing window between **SYSTEM `osk.exe`** starting and writing the per-session key. To make it reliable, the exploit places an **oplock** on:
     58 
     59 ```text
     60 C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml
     61 ```
     62 
     63 When the oplock triggers, the attacker swaps the per-session HKLM key for a registry link, lets the SYSTEM write land, then removes the link.<sup>[[1]](#references)</sup>
     64 
     65 ## Example Exploitation Flow (High Level)
     66 
     67 1. Get current **session ID** from the access token.
     68 2. Start a hidden `osk.exe` instance and sleep briefly (ensure the oplock will trigger).
     69 3. Write attacker-controlled values to:
     70    - `HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk`
     71 4. Set an **oplock** on `C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml`.
     72 5. Trigger **Secure Desktop** (`LockWorkstation()`), causing SYSTEM `atbroker.exe` / `osk.exe` to start.
     73 6. On oplock trigger, replace `HKLM\...\Session<session id>\ATConfig\osk` with a **registry link** to an arbitrary target.
     74 7. Wait briefly for the SYSTEM copy to complete, then remove the link.<sup>[[1]](#references)</sup>
     75 
     76 ## Converting the Primitive to SYSTEM Execution
     77 
     78 One straightforward chain is to overwrite a **service configuration** value (e.g., `ImagePath`) and then start the service. The RegPwn PoC overwrites the `ImagePath` of **`msiserver`** and triggers it by instantiating the **MSI COM object**, resulting in **SYSTEM** code execution.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     79 
     80 ## Related
     81 
     82 For other Secure Desktop / UIAccess behaviors, see:
     83 
     84 [Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass)
     85 
     86 ## References
     87 
     88 - [1] [RIP RegPwn](https://www.mdsec.co.uk/2026/03/rip-regpwn/)
     89 - [2] [RegPwn PoC](https://github.com/mdsecactivebreach/RegPwn)