secure-desktop-accessibility-registry-propagation-regpwn.md (5236B)
1 --- 2 title: "Secure Desktop Accessibility Registry Propagation LPE (RegPwn)" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Secure Desktop Accessibility Registry Propagation LPE (RegPwn) 14 15 ## Overview 16 17 Windows Accessibility features persist user configuration under HKCU and propagate it into per-session HKLM locations. During a **Secure Desktop** transition (lock screen or UAC prompt), **SYSTEM** components re-copy these values. If the **per-session HKLM key is writable by the user**, it becomes a privileged write choke point that can be redirected with **registry symbolic links**, yielding an **arbitrary SYSTEM registry write**.<sup>[[1]](#references)</sup> 18 19 The RegPwn technique abuses that propagation chain with a small race window stabilized via an **opportunistic lock (oplock)** on a file used by `osk.exe`.<sup>[[1]](#references)</sup> 20 21 ## Registry Propagation Chain (Accessibility -> Secure Desktop) 22 23 Example feature: **On-Screen Keyboard** (`osk`). The relevant locations are: 24 25 - **System-wide feature list**: 26 - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs` 27 - **Per-user configuration (user-writable)**: 28 - `HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk` 29 - **Per-session HKLM config (created by `winlogon.exe`, user-writable)**: 30 - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<session id>\ATConfig\osk` 31 - **Secure desktop/default user hive (SYSTEM context)**: 32 - `HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk` 33 34 Propagation during a secure desktop transition (simplified): 35 36 1. **User `atbroker.exe`** copies `HKCU\...\ATConfig\osk` to `HKLM\...\Session<session id>\ATConfig\osk`. 37 2. **SYSTEM `atbroker.exe`** copies `HKLM\...\Session<session id>\ATConfig\osk` to `HKU\.DEFAULT\...\ATConfig\osk`. 38 3. **SYSTEM `osk.exe`** copies `HKU\.DEFAULT\...\ATConfig\osk` back to `HKLM\...\Session<session id>\ATConfig\osk`. 39 40 If the session HKLM subtree is writable by the user, step 2/3 provide a SYSTEM write through a location the user can replace.<sup>[[1]](#references)</sup> 41 42 ## Primitive: Arbitrary SYSTEM Registry Write via Registry Links 43 44 Replace the user-writable per-session key with a **registry symbolic link** that points to an attacker-chosen destination. When the SYSTEM copy occurs, it follows the link and writes attacker-controlled values into the arbitrary target key. 45 46 Key idea: 47 48 - Victim write target (user-writable): 49 - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session<session id>\ATConfig\osk` 50 - Attacker replaces that key with a **registry link** to any other key. 51 - SYSTEM performs the copy and writes into the attacker-chosen key with SYSTEM permissions. 52 53 This yields an **arbitrary SYSTEM registry write** primitive.<sup>[[1]](#references)</sup> 54 55 ## Winning the Race Window with Oplocks 56 57 There is a short timing window between **SYSTEM `osk.exe`** starting and writing the per-session key. To make it reliable, the exploit places an **oplock** on: 58 59 ```text 60 C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml 61 ``` 62 63 When the oplock triggers, the attacker swaps the per-session HKLM key for a registry link, lets the SYSTEM write land, then removes the link.<sup>[[1]](#references)</sup> 64 65 ## Example Exploitation Flow (High Level) 66 67 1. Get current **session ID** from the access token. 68 2. Start a hidden `osk.exe` instance and sleep briefly (ensure the oplock will trigger). 69 3. Write attacker-controlled values to: 70 - `HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATConfig\osk` 71 4. Set an **oplock** on `C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu.xml`. 72 5. Trigger **Secure Desktop** (`LockWorkstation()`), causing SYSTEM `atbroker.exe` / `osk.exe` to start. 73 6. On oplock trigger, replace `HKLM\...\Session<session id>\ATConfig\osk` with a **registry link** to an arbitrary target. 74 7. Wait briefly for the SYSTEM copy to complete, then remove the link.<sup>[[1]](#references)</sup> 75 76 ## Converting the Primitive to SYSTEM Execution 77 78 One straightforward chain is to overwrite a **service configuration** value (e.g., `ImagePath`) and then start the service. The RegPwn PoC overwrites the `ImagePath` of **`msiserver`** and triggers it by instantiating the **MSI COM object**, resulting in **SYSTEM** code execution.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 79 80 ## Related 81 82 For other Secure Desktop / UIAccess behaviors, see: 83 84 [Uiaccess Admin Protection Bypass](/hacktricks/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass) 85 86 ## References 87 88 - [1] [RIP RegPwn](https://www.mdsec.co.uk/2026/03/rip-regpwn/) 89 - [2] [RegPwn PoC](https://github.com/mdsecactivebreach/RegPwn)