[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUSYt3YL8yYAeFudupo33aIx_rtPfn3LqdBqU3XyERjQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1190,"What is the purpose of specifying properties like FOF_NOCONFIRMATION and FOFX_REQUIREELEVATION when using IFileOperation?","These properties control the behavior of the file operation to avoid user interaction. FOF_NOCONFIRMATION suppresses confirmation dialogs, FOF_SILENT hides progress dialogs, and FOFX_REQUIREELEVATION ensures the operation runs with elevated privileges. Properly setting these flags is essential for a silent, automated privilege escalation that does not alert the user.","\u003Cp>These properties control the behavior of the file operation to avoid user interaction. FOF_NOCONFIRMATION suppresses confirmation dialogs, FOF_SILENT hides progress dialogs, and FOFX_REQUIREELEVATION ensures the operation runs with elevated privileges. Properly setting these flags is essential for a silent, automated privilege escalation that does not alert the user.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Funauthorized-file-copying-via-com-component-ifileoperation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-purpose-of-specifying-properties-like-fof_noconfirmation-and-fofx_re-1777480046180","IFileOperation flags, FOF_NOCONFIRMATION, FOFX_REQUIREELEVATION, silent copy, elevation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},288,"Unauthorized file copying via COM component IFileOperation","unauthorized-file-copying-via-com-component-ifileoperation","Learn how to bypass UAC using COM IFileOperation for unauthorized file copying from Windows 7 to 10. Methods include DLL injection and PEB modification.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Analysis of Invoke-WScriptBypassUAC Exploitation in Empire', a method for unauthorized file copying was introduced. Under standard user permissions, wusa could be used to extract cab files into administrator-privileged folders, enabling further filename hijacking and UAC bypass.\u003C\u002Fp>\u003Cp>However, this functionality was removed in Windows 10. So, is there a more universal method?\u003C\u002Fp>\u003Cp>This article will introduce a method applicable from Windows 7 to Windows 10—using the COM component IFileOperation.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Principle\u003C\u002Fli>\u003Cli>Three Implementation Approaches\u003C\u002Fli>\u003Cli>Example Code\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from the workshop at Defcon 25, Ruben Boonen's \"UAC 0day, all day!\"\u003C\u002Fp>\u003Cp>PPT download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FDefCon25\u002Fblob\u002Fmaster\u002FDefCon25_UAC-0day-All-Day_v1.2.pdf\u003C\u002Fp>\u003Cp>Prerequisites for exploiting the COM component IFileOperation to copy files with elevated privileges:\u003C\u002Fp>\u003Cul>\u003Cli>Systems after Windows 7\u003C\u002Fli>\u003Cli>Trusted files in trusted paths (e.g., explorer.exe, powershell.exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, there are three implementation approaches:\u003C\u002Fp>\u003Ch3>1. DLL hijacking or DLL injection\u003C\u002Fh3>\u003Cp>Since trusted files in trusted paths are generally located in directories requiring administrator privileges, DLL hijacking is essentially impossible under normal user permissions.\u003C\u002Fp>\u003Cp>A feasible method is DLL injection.\u003C\u002Fp>\u003Cp>For example, explorer.exe can be subjected to DLL injection under normal user permissions.\u003C\u002Fp>\u003Ch3>2. Modify the PEB structure to deceive PSAPI and invoke the COM component IFileOperation\u003C\u002Fh3>\u003Cp>The COM component uses the Process Status API (PSAPI) to read the Commandline in the process's PEB structure to identify the processes they are running.\u003C\u002Fp>\u003Cp>If the process's Path is changed to a trusted file (e.g., explorer.exe), it can deceive PSAPI and invoke the COM component IFileOperation to achieve privileged file copying.\u003C\u002Fp>\u003Ch3>3. Directly calling COM component IFileOperation through trusted files\u003C\u002Fh3>\u003Cp>For example, powershell.exe is a trusted file and can directly call the COM component IFileOperation\u003C\u002Fp>\u003Ch2>0x03 Implementation Method 1: DLL injection into explorer.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The specific implementation is divided into the following two parts:\u003C\u002Fp>\u003Col>\u003Cli>Injecting the DLL into the process explorer.exe\u003C\u002Fli>\u003Cli>The DLL implements calling the COM component IFileOperation to copy files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>There is already a complete implementation code on GitHub, so you can refer to this project for analysis. The project address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhjc4869\u002FUacBypass\u003C\u002Fp>\u003Cp>(1) The project UacBypassTest implements DLL injection into the process explorer.exe\u003C\u002Fp>\u003Cp>Remove unnecessary functions and retain only the function of injecting UacBypass.dll into the process explorer.exe:\u003C\u002Fp>\u003Cp>Delete Line 58\u003C\u002Fp>\u003Cp>(2) The project UacBypass implements calling the COM component IFileOperation to copy files\u003C\u002Fp>\u003Cp>After compiling this project, the file UacBypass.dll is generated, which implements copying ntwdblib.dll from the same directory to C:\\windows\\System32\u003C\u002Fp>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Run UacBypassTest.exe to inject UacBypass.dll into the explorer.exe process, successfully achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x04 Implementation Method 2: Modify PEB structure, deceive PSAPI, call COM component IFileOperation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the UacBypass project, convert dll to exe, add header files, fix bugs, complete code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Achieved copying c:\\6\\ntwdblib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>\u003Cstrong>Code analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for success is specifying the properties of this COM component (requires elevated privileges)\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fbb775799.aspx\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Property description:\u003C\u002Fp>\u003Cul>\u003Cli>FOF_NOCONFIRMATION: No confirmation dialog pops up\u003C\u002Fli>\u003Cli>FOF_SILENT: No dialog pops up\u003C\u002Fli>\u003Cli>FOFX_SHOWELEVATIONPROMPT: Elevation prompt required\u003C\u002Fli>\u003Cli>FOFX_NOCOPYHOOKS: Do not use copy hooks\u003C\u002Fli>\u003Cli>FOFX_REQUIREELEVATION: Default elevation required\u003C\u002Fli>\u003Cli>FOF_NOERRORUI: No error dialog on failure\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Running the exe directly triggers a UAC confirmation dialog indicating insufficient permissions; if allowed, file copying can proceed\u003C\u002Fp>\u003Cp>Next, functionality to modify the PEB structure needs to be added to deceive PSAPI. The following locations must be modified:\u003C\u002Fp>\u003Cul>\u003Cli>ImagePathName in _RTL_USER_PROCESS_PARAMETERS\u003C\u002Fli>\u003Cli>FullDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003Cli>BaseDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CommandLine in _RTL_USER_PROCESS_PARAMETERS does not need modification. This attribute can be viewed via Process Explorer; for greater deception, it can optionally be altered\u003C\u002Fp>\u003Cp>Here, I referenced the implementation code of supMasqueradeProcess() in UACME at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002F143ead4db6b57a84478c9883023fbe5d64ac277b\u002FSource\u002FAkagi\u002Fsup.c#L947\u003C\u002Fp>\u003Cp>I made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Instead of using the ntdll.lib file (included after installing DDK), obtain NTAPI through ntdll\u003C\u002Fli>\u003Cli>Extract key code\u003C\u002Fli>\u003Cli>Fix bugs\u003C\u002Fli>\u003Cli>Add functionality to call the COM component IFileOperation for file copying\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code modifies the current process's PEB structure to deceive PSAPI into recognizing it as explorer.exe, then calls the COM component IFileOperation to achieve file copying\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>The current process is modified to explorer.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016707803_0_dfd4bf8021.jpeg\">\u003C\u002Fp>\u003Cp>File copying succeeded without triggering the UAC confirmation dialog, achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x05 Implementation Method 3: Calling the COM component IFileOperation via powershell.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First compile a COM component in C# to call IFileOperation for file copying, then invoke this COM component via PowerShell\u003C\u002Fp>\u003Ch3>1. Write COM component\u003C\u002Fh3>\u003Cp>Code reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Ftree\u002Fmaster\u002FBypass-UAC\u002FFileOperations\u002FFileOperations\u003C\u002Fp>\u003Cp>After successful compilation, generate FileOperation.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source project referenced by Ruben Boonen (b33f@FuzzySecurity):\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmlaily\u002FMSDNMagazine2007-.NET-Matters-IFileOperation-in-Windows-Vista\u003C\u002Fp>\u003Cp>He made modifications (such as changing class names) based on this, enabling PowerShell to directly call the COM component, which is a great feature\u003C\u002Fp>\u003Ch3>2. Call this COM component via PowerShell\u003C\u002Fh3>\u003Cp>There are two methods:\u003C\u002Fp>\u003Cp>(1) [System.Reflection.Assembly]::LoadFile($Path)\u003C\u002Fp>\u003Cp>Load the file directly\u003C\u002Fp>\u003Cp>(2) [Reflection.Assembly]::Load($bytes)\u003C\u002Fp>\u003Cp>Compress the file into a string stored in an array. Refer to Matthew Graeber's method, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2012\u002F12\u002Fin-memory-dll-loading.html\u003C\u002Fp>\u003Cp>Can directly output usable PowerShell code\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Comparison of the two methods was introduced in the previous article 'Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile'\u003C\u002Fp>\u003Cp>Complete implementation code for Method 3 can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Febbb8991a8a051b48c05ce676524a1ba787dbf0c\u002FBypass-UAC\u002FBypass-UAC.ps1#L1082\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>Executing PowerShell script, loading COM component IFileOperation. Since powershell.exe is a trusted process, no UAC confirmation dialog pops up, successfully achieving privilege escalation for file copying\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COM component IFileOperation is applicable from Win7 to Win10, so the privilege escalation file copying method is also usable\u003C\u002Fp>\u003Cp>For explorer.exe, loading high-privilege COM components does not trigger UAC dialog.\u003C\u002Fp>\u003Cp>This article has already implemented the method to simulate explorer.exe. So, are there other usable COM components? And what 'privilege escalation operations' can they accomplish?\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced three methods for privilege escalation file copying via COM component IFileOperation, organized and developed implementation code that can be used for direct testing\u003C\u002Fp>\u003Cp>Finally, thanks to Ruben Boonen (b33f@FuzzySecurity) for his help in my research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Analysis of Invoke-WScriptBypassUAC Exploitation in Empire', a method for unauthorized file copying was introduced. Under standard user permissions, wusa could be used to extract cab files into administrator-privileged folders, enabling further filename hijacking and UAC bypass.\u003C\u002Fp>\u003Cp>However, this functionality was removed in Windows 10. So, is there a more universal method?\u003C\u002Fp>\u003Cp>This article will introduce a method applicable from Windows 7 to Windows 10—using the COM component IFileOperation.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Principle\u003C\u002Fli>\u003Cli>Three Implementation Approaches\u003C\u002Fli>\u003Cli>Example Code\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from the workshop at Defcon 25, Ruben Boonen's \"UAC 0day, all day!\"\u003C\u002Fp>\u003Cp>PPT download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FDefCon25\u002Fblob\u002Fmaster\u002FDefCon25_UAC-0day-All-Day_v1.2.pdf\u003C\u002Fp>\u003Cp>Prerequisites for exploiting the COM component IFileOperation to copy files with elevated privileges:\u003C\u002Fp>\u003Cul>\u003Cli>Systems after Windows 7\u003C\u002Fli>\u003Cli>Trusted files in trusted paths (e.g., explorer.exe, powershell.exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, there are three implementation approaches:\u003C\u002Fp>\u003Ch3>1. DLL hijacking or DLL injection\u003C\u002Fh3>\u003Cp>Since trusted files in trusted paths are generally located in directories requiring administrator privileges, DLL hijacking is essentially impossible under normal user permissions.\u003C\u002Fp>\u003Cp>A feasible method is DLL injection.\u003C\u002Fp>\u003Cp>For example, explorer.exe can be subjected to DLL injection under normal user permissions.\u003C\u002Fp>\u003Ch3>2. Modify the PEB structure to deceive PSAPI and invoke the COM component IFileOperation\u003C\u002Fh3>\u003Cp>The COM component uses the Process Status API (PSAPI) to read the Commandline in the process's PEB structure to identify the processes they are running.\u003C\u002Fp>\u003Cp>If the process's Path is changed to a trusted file (e.g., explorer.exe), it can deceive PSAPI and invoke the COM component IFileOperation to achieve privileged file copying.\u003C\u002Fp>\u003Ch3>3. Directly calling COM component IFileOperation through trusted files\u003C\u002Fh3>\u003Cp>For example, powershell.exe is a trusted file and can directly call the COM component IFileOperation\u003C\u002Fp>\u003Ch2>0x03 Implementation Method 1: DLL injection into explorer.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The specific implementation is divided into the following two parts:\u003C\u002Fp>\u003Col>\u003Cli>Injecting the DLL into the process explorer.exe\u003C\u002Fli>\u003Cli>The DLL implements calling the COM component IFileOperation to copy files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>There is already a complete implementation code on GitHub, so you can refer to this project for analysis. The project address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhjc4869\u002FUacBypass\u003C\u002Fp>\u003Cp>(1) The project UacBypassTest implements DLL injection into the process explorer.exe\u003C\u002Fp>\u003Cp>Remove unnecessary functions and retain only the function of injecting UacBypass.dll into the process explorer.exe:\u003C\u002Fp>\u003Cp>Delete Line 58\u003C\u002Fp>\u003Cp>(2) The project UacBypass implements calling the COM component IFileOperation to copy files\u003C\u002Fp>\u003Cp>After compiling this project, the file UacBypass.dll is generated, which implements copying ntwdblib.dll from the same directory to C:\\windows\\System32\u003C\u002Fp>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Run UacBypassTest.exe to inject UacBypass.dll into the explorer.exe process, successfully achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x04 Implementation Method 2: Modify PEB structure, deceive PSAPI, call COM component IFileOperation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the UacBypass project, convert dll to exe, add header files, fix bugs, complete code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Achieved copying c:\\6\\ntwdblib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>\u003Cstrong>Code analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for success is specifying the properties of this COM component (requires elevated privileges)\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fbb775799.aspx\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Property description:\u003C\u002Fp>\u003Cul>\u003Cli>FOF_NOCONFIRMATION: No confirmation dialog pops up\u003C\u002Fli>\u003Cli>FOF_SILENT: No dialog pops up\u003C\u002Fli>\u003Cli>FOFX_SHOWELEVATIONPROMPT: Elevation prompt required\u003C\u002Fli>\u003Cli>FOFX_NOCOPYHOOKS: Do not use copy hooks\u003C\u002Fli>\u003Cli>FOFX_REQUIREELEVATION: Default elevation required\u003C\u002Fli>\u003Cli>FOF_NOERRORUI: No error dialog on failure\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Running the exe directly triggers a UAC confirmation dialog indicating insufficient permissions; if allowed, file copying can proceed\u003C\u002Fp>\u003Cp>Next, functionality to modify the PEB structure needs to be added to deceive PSAPI. The following locations must be modified:\u003C\u002Fp>\u003Cul>\u003Cli>ImagePathName in _RTL_USER_PROCESS_PARAMETERS\u003C\u002Fli>\u003Cli>FullDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003Cli>BaseDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CommandLine in _RTL_USER_PROCESS_PARAMETERS does not need modification. This attribute can be viewed via Process Explorer; for greater deception, it can optionally be altered\u003C\u002Fp>\u003Cp>Here, I referenced the implementation code of supMasqueradeProcess() in UACME at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002F143ead4db6b57a84478c9883023fbe5d64ac277b\u002FSource\u002FAkagi\u002Fsup.c#L947\u003C\u002Fp>\u003Cp>I made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Instead of using the ntdll.lib file (included after installing DDK), obtain NTAPI through ntdll\u003C\u002Fli>\u003Cli>Extract key code\u003C\u002Fli>\u003Cli>Fix bugs\u003C\u002Fli>\u003Cli>Add functionality to call the COM component IFileOperation for file copying\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code modifies the current process's PEB structure to deceive PSAPI into recognizing it as explorer.exe, then calls the COM component IFileOperation to achieve file copying\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>The current process is modified to explorer.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016707803_0_dfd4bf8021-1.jpeg\">\u003C\u002Fp>\u003Cp>File copying succeeded without triggering the UAC confirmation dialog, achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x05 Implementation Method 3: Calling the COM component IFileOperation via powershell.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First compile a COM component in C# to call IFileOperation for file copying, then invoke this COM component via PowerShell\u003C\u002Fp>\u003Ch3>1. Write COM component\u003C\u002Fh3>\u003Cp>Code reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Ftree\u002Fmaster\u002FBypass-UAC\u002FFileOperations\u002FFileOperations\u003C\u002Fp>\u003Cp>After successful compilation, generate FileOperation.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source project referenced by Ruben Boonen (b33f@FuzzySecurity):\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmlaily\u002FMSDNMagazine2007-.NET-Matters-IFileOperation-in-Windows-Vista\u003C\u002Fp>\u003Cp>He made modifications (such as changing class names) based on this, enabling PowerShell to directly call the COM component, which is a great feature\u003C\u002Fp>\u003Ch3>2. Call this COM component via PowerShell\u003C\u002Fh3>\u003Cp>There are two methods:\u003C\u002Fp>\u003Cp>(1) [System.Reflection.Assembly]::LoadFile($Path)\u003C\u002Fp>\u003Cp>Load the file directly\u003C\u002Fp>\u003Cp>(2) [Reflection.Assembly]::Load($bytes)\u003C\u002Fp>\u003Cp>Compress the file into a string stored in an array. Refer to Matthew Graeber's method, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2012\u002F12\u002Fin-memory-dll-loading.html\u003C\u002Fp>\u003Cp>Can directly output usable PowerShell code\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Comparison of the two methods was introduced in the previous article 'Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile'\u003C\u002Fp>\u003Cp>Complete implementation code for Method 3 can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Febbb8991a8a051b48c05ce676524a1ba787dbf0c\u002FBypass-UAC\u002FBypass-UAC.ps1#L1082\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>Executing PowerShell script, loading COM component IFileOperation. Since powershell.exe is a trusted process, no UAC confirmation dialog pops up, successfully achieving privilege escalation for file copying\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COM component IFileOperation is applicable from Win7 to Win10, so the privilege escalation file copying method is also usable\u003C\u002Fp>\u003Cp>For explorer.exe, loading high-privilege COM components does not trigger UAC dialog.\u003C\u002Fp>\u003Cp>This article has already implemented the method to simulate explorer.exe. So, are there other usable COM components? And what 'privilege escalation operations' can they accomplish?\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced three methods for privilege escalation file copying via COM component IFileOperation, organized and developed implementation code that can be used for direct testing\u003C\u002Fp>\u003Cp>Finally, thanks to Ruben Boonen (b33f@FuzzySecurity) for his help in my research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",31,"Onedaysec",5,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Unauthorized File Copy via COM IFileOperation: UAC Bypass Methods","UAC bypass, IFileOperation COM, unauthorized file copy, Windows security, DLL injection, PEB modification, privilege escalation, Windows 7 to 10, exploit techniques, trusted files",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],1189,1188,1187,1186,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.004Z","2026-07-23T16:02:39.381Z","draft","2026-07-23T16:17:18.089Z"]