[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDXuaNBL2G-mvNZLjgMGDXSVecYNI43TuMmjdQBLtKec":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},598,"What makes SilentCleanup a good target for UAC bypass?","SilentCleanup is a scheduled task that can be launched by standard users (Authenticated Users) but automatically elevates to high privileges (`RunLevel = Highest`). This lax permission control, combined with its use of the `%windir%` environment variable in the startup path, provides a hijacking opportunity. Similar to the [sdclt.exe bypass](\u002Fnews\u002Fstudy-notes-of-using-sdclt-exe-to-bypass-uac), it fits the pattern of finding high-integrity programs that are triggerable by low-integrity users and whose startup process can be altered.","\u003Cp>SilentCleanup is a scheduled task that can be launched by standard users (Authenticated Users) but automatically elevates to high privileges (`RunLevel = Highest`). This lax permission control, combined with its use of the `%windir%` environment variable in the startup path, provides a hijacking opportunity. Similar to the [sdclt.exe bypass](\u002Fnews\u002Fstudy-notes-of-using-sdclt-exe-to-bypass-uac), it fits the pattern of finding high-integrity programs that are triggerable by low-integrity users and whose startup process can be altered.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-of-using-silentcleanup-to-bypass-uac\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-makes-silentcleanup-a-good-target-for-uac-bypass-1777482810744","UAC bypass, SilentCleanup, permission control, scheduled task, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},147,"Study Notes of using SilentCleanup to bypass UAC","study-notes-of-using-silentcleanup-to-bypass-uac","Learn how to bypass UAC on Windows 10\u002F8 using SilentCleanup scheduled task. Exploit environment variables to hijack cleanmgr.exe for privilege escalation. Includes defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned a technique for bypassing UAC on Windows 10 from James Forshaw's blog. This method is implemented through scripting, and Microsoft has not yet patched this bypass (expected to be fixed in Windows 10 RS3). Through my study and testing, this method is also applicable to Windows 8, and the bypass approach introduced in the article is very worthy of learning. Therefore, I have compiled it into an article to share with everyone.\u003C\u002Fp>\u003Cp>The article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftyranidslair.blogspot.co.uk\u002F2017\u002F05\u002Fexploiting-environment-variables-in.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Bypass approach\u003C\u002Fli>\u003Cli>Exploitation method\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Bypass approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I have previously shared some insights on bypassing UAC approaches. You can refer to the following articles:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FStudy-Notes-of-using-sdclt.exe-to-bypass-UAC\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FStudy-Notes-Weekly-No.1(Monitor-WMI_ExportsToC++_Use-DiskCleanup-bypass-UAC)\u003C\u002Fp>\u003Cp>In my opinion, finding methods to bypass UAC can be divided into the following two steps:\u003C\u002Fp>\u003Cp>1. Finding programs with lax permission controls\u003C\u002Fp>\u003Cp>Typically characterized by:\u003C\u002Fp>\u003Cul>\u003Cli>Launching programs with standard user privileges\u003C\u002Fli>\u003Cli>Programs that start with high privileges by default, usually marked as Highest\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Whether the program's startup process can be hijacked\u003C\u002Fp>\u003Cul>\u003Cli>Whether the startup path can be hijacked\u003C\u002Fli>\u003Cli>Whether files loaded during startup (such as DLLs) can be hijacked\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Corresponding to James Forshaw's method, it also prioritizes finding programs with lax permission controls—SilentCleanup in scheduled tasks\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson previously introduced a method to bypass UAC using SilentCleanup, which has now been patched. The article address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F07\u002F22\u002Fbypassing-uac-on-windows-10-using-disk-cleanup\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>SilentCleanup in Scheduled Tasks:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Can be launched with standard user privileges\u003C\u002Fli>\u003Cli>Automatically elevates to high privileges after launch\u003C\u002Fli>\u003C\u002Ful>\u003Cp>More details can be obtained via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$task = Get-ScheduledTask SilentCleanup\u003Cbr>$task.Principal\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows 7 default PowerShell version 2.0 does not support Get-ScheduledTask operation\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017273177_0_a789547a62.jpeg\">\u003C\u002Fp>\u003Cp>Authenticated Users indicates it can be launched with standard user privileges\u003C\u002Fp>\u003Cp>RunLevel as Highest indicates it launches with high privileges\u003C\u002Fp>\u003Cp>To view launch parameters, use the following PowerShell code:\u003C\u002Fp>\u003Cp>$task.Actions[0]\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017292804_1_4ad96b4ea3.jpeg\">\u003C\u002Fp>\u003Cp>The startup parameter is %windir%\\system32\\cleanmgr.exe\u003C\u002Fp>\u003Cp>There is an exploitable aspect here—the environment variable %windir%\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can view the environment variable %windir% via set windir\u003C\u002Fp>\u003Cp>%windir% defaults to c:\\Windows\u003C\u002Fp>\u003Cp>If the current system environment variable is modified to point to another path, then a hijack is achieved here\u003C\u002Fp>\u003Cp>\u003Cstrong>For example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set %windir% to c:\\test\u003C\u002Fp>\u003Cp>Save payload.exe as cleanmgr.exe under c:\\test\\system32\\\u003C\u002Fp>\u003Cp>Then when starting the scheduled task SilentCleanup, payload.exe will be launched with high privileges, achieving UAC bypass\u003C\u002Fp>\u003Cp>\u003Cstrong>A more direct exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set %windir% to cmd \u002FK, then cmd.exe will pop up when starting the scheduled task SilentCleanup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameters must be added after cmd, otherwise it cannot start normally due to parameter issues\u003C\u002Fp>\u003Cp>\u002Fk indicates that the popped-up cmd.exe does not exit after executing the code\u003C\u002Fp>\u003Cp>To increase stealth (many programs need to call the environment variable %windir% during startup), while executing cmd, also delete the newly added registry key windir. The following code can be used:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\Environment \u002Fv windir \u002Fd \"cmd \u002FK reg delete hkcu\\Environment \u002Fv windir \u002Ff &amp;&amp; REM \"\u003Cbr>schtasks \u002FRun \u002FTN \\Microsoft\\Windows\\DiskCleanup\\SilentCleanup \u002FI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code comes from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F729b334bf9dc0f38184dbd47ae3f52d0#file-disk_cleanup_uac_bypass-bat\u003C\u002Fp>\u003Cp>Setting the environment variable to cmd \u002FK reg delete hkcu\\Environment \u002Fv windir \u002Ff &amp;&amp; REM will cause cmd.exe to pop up when starting the scheduled task SilentCleanup, then execute the command to delete the registry key: reg delete hkcu\\Environment \u002Fv windir \u002Ff\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322662_2_5c25e60a0a.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the parameter is changed to \u002Fa, then cmd.exe will exit immediately after executing the following command\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Defense\u003C\u002Fh3>\u003Cp>Modify the startup parameters of the scheduled task SilentCleanup by removing environment variables and replacing them with c:\\Windows to lock the path.\u003C\u002Fp>\u003Cp>\u003Cstrong>Administrator privileges:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$action = New-ScheduledTaskAction -Execute $env:windir\\System32\\cleanmgr.exe -Argument \"\u002Fautoclean \u002Fd $env:systemdrive\"\u003Cbr>Set-ScheduledTask SilentCleanup -TaskPath \\Microsoft\\Windows\\DiskCleanup -Action $action\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is sourced from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F9ef39228ba0acc6aa4039d2218006546#file-fix_diskclean_uac_bypass-ps1\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017373645_3_20e758fb34.jpeg\">\u003C\u002Fp>\u003Cp>The startup parameters of the scheduled task SilentCleanup have been modified to c:\\windows\\system32\\cleanmgr.exe, preventing hijacking through modification of the environment variable %windir%.\u003C\u002Fp>\u003Ch3>2. Detection\u003C\u002Fh3>\u003Cp>Use PowerShell to search for exploitable services in scheduled tasks with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$tasks = Get-ScheduledTask | \u003Cbr>    Where-Object { $_.Principal.RunLevel -ne \"Limited\" -and \u003Cbr>                   $_.Principal.LogonType -ne \"ServiceAccount\" -and \u003Cbr>                   $_.State -ne \"Disabled\" -and \u003Cbr>                   $_.Actions[0].CimClass.CimClassName -eq \"MSFT_TaskExecAction\" }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F92e1c7074a9a7b0d5d021e9218e34fe7#file-get_scheduled_tasks-ps1\u003C\u002Fp>\u003Cp>As shown below, there are a total of four services available for exploitation. Testing shows that the other three are not practically exploitable; only SilentCleanup is effective.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395823_4_206fdcde93.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method is also applicable to the Win8 environment. The complete operation is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017438043_5_4e96e5f178.png\">\u003C\u002Fp>\u003Cp>The Win7 system does not include the scheduled task SilentCleanup, so it cannot be exploited.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing UAC through the scheduled task SilentCleanup. This method only requires writing a key value to the current user's registry via a script, making it simple and effective.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned a technique for bypassing UAC on Windows 10 from James Forshaw's blog. This method is implemented through scripting, and Microsoft has not yet patched this bypass (expected to be fixed in Windows 10 RS3). Through my study and testing, this method is also applicable to Windows 8, and the bypass approach introduced in the article is very worthy of learning. Therefore, I have compiled it into an article to share with everyone.\u003C\u002Fp>\u003Cp>The article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftyranidslair.blogspot.co.uk\u002F2017\u002F05\u002Fexploiting-environment-variables-in.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Bypass approach\u003C\u002Fli>\u003Cli>Exploitation method\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Bypass approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I have previously shared some insights on bypassing UAC approaches. You can refer to the following articles:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FStudy-Notes-of-using-sdclt.exe-to-bypass-UAC\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FStudy-Notes-Weekly-No.1(Monitor-WMI_ExportsToC++_Use-DiskCleanup-bypass-UAC)\u003C\u002Fp>\u003Cp>In my opinion, finding methods to bypass UAC can be divided into the following two steps:\u003C\u002Fp>\u003Cp>1. Finding programs with lax permission controls\u003C\u002Fp>\u003Cp>Typically characterized by:\u003C\u002Fp>\u003Cul>\u003Cli>Launching programs with standard user privileges\u003C\u002Fli>\u003Cli>Programs that start with high privileges by default, usually marked as Highest\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Whether the program's startup process can be hijacked\u003C\u002Fp>\u003Cul>\u003Cli>Whether the startup path can be hijacked\u003C\u002Fli>\u003Cli>Whether files loaded during startup (such as DLLs) can be hijacked\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Corresponding to James Forshaw's method, it also prioritizes finding programs with lax permission controls—SilentCleanup in scheduled tasks\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson previously introduced a method to bypass UAC using SilentCleanup, which has now been patched. The article address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F07\u002F22\u002Fbypassing-uac-on-windows-10-using-disk-cleanup\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>SilentCleanup in Scheduled Tasks:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Can be launched with standard user privileges\u003C\u002Fli>\u003Cli>Automatically elevates to high privileges after launch\u003C\u002Fli>\u003C\u002Ful>\u003Cp>More details can be obtained via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$task = Get-ScheduledTask SilentCleanup\u003Cbr>$task.Principal\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows 7 default PowerShell version 2.0 does not support Get-ScheduledTask operation\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017273177_0_a789547a62-1.jpeg\">\u003C\u002Fp>\u003Cp>Authenticated Users indicates it can be launched with standard user privileges\u003C\u002Fp>\u003Cp>RunLevel as Highest indicates it launches with high privileges\u003C\u002Fp>\u003Cp>To view launch parameters, use the following PowerShell code:\u003C\u002Fp>\u003Cp>$task.Actions[0]\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017292804_1_4ad96b4ea3-1.jpeg\">\u003C\u002Fp>\u003Cp>The startup parameter is %windir%\\system32\\cleanmgr.exe\u003C\u002Fp>\u003Cp>There is an exploitable aspect here—the environment variable %windir%\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can view the environment variable %windir% via set windir\u003C\u002Fp>\u003Cp>%windir% defaults to c:\\Windows\u003C\u002Fp>\u003Cp>If the current system environment variable is modified to point to another path, then a hijack is achieved here\u003C\u002Fp>\u003Cp>\u003Cstrong>For example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set %windir% to c:\\test\u003C\u002Fp>\u003Cp>Save payload.exe as cleanmgr.exe under c:\\test\\system32\\\u003C\u002Fp>\u003Cp>Then when starting the scheduled task SilentCleanup, payload.exe will be launched with high privileges, achieving UAC bypass\u003C\u002Fp>\u003Cp>\u003Cstrong>A more direct exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Set %windir% to cmd \u002FK, then cmd.exe will pop up when starting the scheduled task SilentCleanup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameters must be added after cmd, otherwise it cannot start normally due to parameter issues\u003C\u002Fp>\u003Cp>\u002Fk indicates that the popped-up cmd.exe does not exit after executing the code\u003C\u002Fp>\u003Cp>To increase stealth (many programs need to call the environment variable %windir% during startup), while executing cmd, also delete the newly added registry key windir. The following code can be used:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\Environment \u002Fv windir \u002Fd \"cmd \u002FK reg delete hkcu\\Environment \u002Fv windir \u002Ff &amp;&amp; REM \"\u003Cbr>schtasks \u002FRun \u002FTN \\Microsoft\\Windows\\DiskCleanup\\SilentCleanup \u002FI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code comes from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F729b334bf9dc0f38184dbd47ae3f52d0#file-disk_cleanup_uac_bypass-bat\u003C\u002Fp>\u003Cp>Setting the environment variable to cmd \u002FK reg delete hkcu\\Environment \u002Fv windir \u002Ff &amp;&amp; REM will cause cmd.exe to pop up when starting the scheduled task SilentCleanup, then execute the command to delete the registry key: reg delete hkcu\\Environment \u002Fv windir \u002Ff\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322662_2_5c25e60a0a-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the parameter is changed to \u002Fa, then cmd.exe will exit immediately after executing the following command\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Defense\u003C\u002Fh3>\u003Cp>Modify the startup parameters of the scheduled task SilentCleanup by removing environment variables and replacing them with c:\\Windows to lock the path.\u003C\u002Fp>\u003Cp>\u003Cstrong>Administrator privileges:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$action = New-ScheduledTaskAction -Execute $env:windir\\System32\\cleanmgr.exe -Argument \"\u002Fautoclean \u002Fd $env:systemdrive\"\u003Cbr>Set-ScheduledTask SilentCleanup -TaskPath \\Microsoft\\Windows\\DiskCleanup -Action $action\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is sourced from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F9ef39228ba0acc6aa4039d2218006546#file-fix_diskclean_uac_bypass-ps1\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017373645_3_20e758fb34-1.jpeg\">\u003C\u002Fp>\u003Cp>The startup parameters of the scheduled task SilentCleanup have been modified to c:\\windows\\system32\\cleanmgr.exe, preventing hijacking through modification of the environment variable %windir%.\u003C\u002Fp>\u003Ch3>2. Detection\u003C\u002Fh3>\u003Cp>Use PowerShell to search for exploitable services in scheduled tasks with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$tasks = Get-ScheduledTask | \u003Cbr>    Where-Object { $_.Principal.RunLevel -ne \"Limited\" -and \u003Cbr>                   $_.Principal.LogonType -ne \"ServiceAccount\" -and \u003Cbr>                   $_.State -ne \"Disabled\" -and \u003Cbr>                   $_.Actions[0].CimClass.CimClassName -eq \"MSFT_TaskExecAction\" }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is from https:\u002F\u002Fgist.github.com\u002Ftyranid\u002F92e1c7074a9a7b0d5d021e9218e34fe7#file-get_scheduled_tasks-ps1\u003C\u002Fp>\u003Cp>As shown below, there are a total of four services available for exploitation. Testing shows that the other three are not practically exploitable; only SilentCleanup is effective.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395823_4_206fdcde93-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method is also applicable to the Win8 environment. The complete operation is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017438043_5_4e96e5f178-1.png\">\u003C\u002Fp>\u003Cp>The Win7 system does not include the scheduled task SilentCleanup, so it cannot be exploited.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of bypassing UAC through the scheduled task SilentCleanup. This method only requires writing a key value to the current user's registry via a script, making it simple and effective.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",933,"Onedaysec",4,"published","2026-02-02T07:38:21.455Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass UAC with SilentCleanup: Windows 10\u002F8 Exploit Guide","UAC bypass, SilentCleanup, Windows 10 exploit, privilege escalation, scheduled task hijacking, environment variable attack, James Forshaw, security bypass, Windows 8, cleanmgr.exe",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],600,599,597,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.479Z","2026-07-23T16:01:49.229Z","draft","2026-07-23T16:13:38.919Z"]