Windows Escalate UAC Protection Bypass...

- AV AC AU C I A
发布: 2016-12-02
修订: 2025-04-13

This Metasploit module will bypass Windows UAC by hijacking a special key in the Registry under the current user hive, and inserting a custom command that will get invoked when the Windows Event Viewer is launched. It will spawn a second shell that has the UAC flag turned off. This Metasploit module modifies a registry key, but cleans up the key once the payload has been invoked. The module does not require the architecture of the payload to match the OS. If specifying EXE::Custom your DLL should call ExitProcess() after starting your payload in a separate process.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息