[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frTR2wyMZZdINM5hbiVc-rWbx5Dse7NOqjLT5CsaHr6o":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1188,"Why does modifying the PEB structure allow an attacker to bypass UAC when using IFileOperation?","The COM component IFileOperation uses the Process Status API (PSAPI) to read the process's PEB structure, specifically the ImagePathName and DLL names, to determine if it's a trusted process. By modifying these fields to mimic a trusted file like explorer.exe, the process can invoke IFileOperation with elevated privileges without triggering a UAC confirmation dialog. This technique is similar in concept to other UAC bypass methods, such as [Bypassing UAC via COM Component IARPUninstallStringLauncher](\u002Fnews\u002Fbypassing-uac-via-com-component-iarpuninstallstringlauncher).","\u003Cp>The COM component IFileOperation uses the Process Status API (PSAPI) to read the process&#39;s PEB structure, specifically the ImagePathName and DLL names, to determine if it&#39;s a trusted process. By modifying these fields to mimic a trusted file like explorer.exe, the process can invoke IFileOperation with elevated privileges without triggering a UAC confirmation dialog. This technique is similar in concept to other UAC bypass methods, such as [Bypassing UAC via COM Component IARPUninstallStringLauncher](\u002Fnews\u002Fbypassing-uac-via-com-component-iarpuninstallstringlauncher).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Funauthorized-file-copying-via-com-component-ifileoperation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-does-modifying-the-peb-structure-allow-an-attacker-to-bypass-uac-when-using--1777480046038","PEB structure, PSAPI, masquerading, trusted process, elevation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},288,"Unauthorized file copying via COM component IFileOperation","unauthorized-file-copying-via-com-component-ifileoperation","Learn how to bypass UAC using COM IFileOperation for unauthorized file copying from Windows 7 to 10. Methods include DLL injection and PEB modification.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Analysis of Invoke-WScriptBypassUAC Exploitation in Empire', a method for unauthorized file copying was introduced. Under standard user permissions, wusa could be used to extract cab files into administrator-privileged folders, enabling further filename hijacking and UAC bypass.\u003C\u002Fp>\u003Cp>However, this functionality was removed in Windows 10. So, is there a more universal method?\u003C\u002Fp>\u003Cp>This article will introduce a method applicable from Windows 7 to Windows 10—using the COM component IFileOperation.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Principle\u003C\u002Fli>\u003Cli>Three Implementation Approaches\u003C\u002Fli>\u003Cli>Example Code\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from the workshop at Defcon 25, Ruben Boonen's \"UAC 0day, all day!\"\u003C\u002Fp>\u003Cp>PPT download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FDefCon25\u002Fblob\u002Fmaster\u002FDefCon25_UAC-0day-All-Day_v1.2.pdf\u003C\u002Fp>\u003Cp>Prerequisites for exploiting the COM component IFileOperation to copy files with elevated privileges:\u003C\u002Fp>\u003Cul>\u003Cli>Systems after Windows 7\u003C\u002Fli>\u003Cli>Trusted files in trusted paths (e.g., explorer.exe, powershell.exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, there are three implementation approaches:\u003C\u002Fp>\u003Ch3>1. DLL hijacking or DLL injection\u003C\u002Fh3>\u003Cp>Since trusted files in trusted paths are generally located in directories requiring administrator privileges, DLL hijacking is essentially impossible under normal user permissions.\u003C\u002Fp>\u003Cp>A feasible method is DLL injection.\u003C\u002Fp>\u003Cp>For example, explorer.exe can be subjected to DLL injection under normal user permissions.\u003C\u002Fp>\u003Ch3>2. Modify the PEB structure to deceive PSAPI and invoke the COM component IFileOperation\u003C\u002Fh3>\u003Cp>The COM component uses the Process Status API (PSAPI) to read the Commandline in the process's PEB structure to identify the processes they are running.\u003C\u002Fp>\u003Cp>If the process's Path is changed to a trusted file (e.g., explorer.exe), it can deceive PSAPI and invoke the COM component IFileOperation to achieve privileged file copying.\u003C\u002Fp>\u003Ch3>3. Directly calling COM component IFileOperation through trusted files\u003C\u002Fh3>\u003Cp>For example, powershell.exe is a trusted file and can directly call the COM component IFileOperation\u003C\u002Fp>\u003Ch2>0x03 Implementation Method 1: DLL injection into explorer.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The specific implementation is divided into the following two parts:\u003C\u002Fp>\u003Col>\u003Cli>Injecting the DLL into the process explorer.exe\u003C\u002Fli>\u003Cli>The DLL implements calling the COM component IFileOperation to copy files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>There is already a complete implementation code on GitHub, so you can refer to this project for analysis. The project address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhjc4869\u002FUacBypass\u003C\u002Fp>\u003Cp>(1) The project UacBypassTest implements DLL injection into the process explorer.exe\u003C\u002Fp>\u003Cp>Remove unnecessary functions and retain only the function of injecting UacBypass.dll into the process explorer.exe:\u003C\u002Fp>\u003Cp>Delete Line 58\u003C\u002Fp>\u003Cp>(2) The project UacBypass implements calling the COM component IFileOperation to copy files\u003C\u002Fp>\u003Cp>After compiling this project, the file UacBypass.dll is generated, which implements copying ntwdblib.dll from the same directory to C:\\windows\\System32\u003C\u002Fp>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Run UacBypassTest.exe to inject UacBypass.dll into the explorer.exe process, successfully achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x04 Implementation Method 2: Modify PEB structure, deceive PSAPI, call COM component IFileOperation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the UacBypass project, convert dll to exe, add header files, fix bugs, complete code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Achieved copying c:\\6\\ntwdblib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>\u003Cstrong>Code analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for success is specifying the properties of this COM component (requires elevated privileges)\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fbb775799.aspx\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Property description:\u003C\u002Fp>\u003Cul>\u003Cli>FOF_NOCONFIRMATION: No confirmation dialog pops up\u003C\u002Fli>\u003Cli>FOF_SILENT: No dialog pops up\u003C\u002Fli>\u003Cli>FOFX_SHOWELEVATIONPROMPT: Elevation prompt required\u003C\u002Fli>\u003Cli>FOFX_NOCOPYHOOKS: Do not use copy hooks\u003C\u002Fli>\u003Cli>FOFX_REQUIREELEVATION: Default elevation required\u003C\u002Fli>\u003Cli>FOF_NOERRORUI: No error dialog on failure\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Running the exe directly triggers a UAC confirmation dialog indicating insufficient permissions; if allowed, file copying can proceed\u003C\u002Fp>\u003Cp>Next, functionality to modify the PEB structure needs to be added to deceive PSAPI. The following locations must be modified:\u003C\u002Fp>\u003Cul>\u003Cli>ImagePathName in _RTL_USER_PROCESS_PARAMETERS\u003C\u002Fli>\u003Cli>FullDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003Cli>BaseDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CommandLine in _RTL_USER_PROCESS_PARAMETERS does not need modification. This attribute can be viewed via Process Explorer; for greater deception, it can optionally be altered\u003C\u002Fp>\u003Cp>Here, I referenced the implementation code of supMasqueradeProcess() in UACME at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002F143ead4db6b57a84478c9883023fbe5d64ac277b\u002FSource\u002FAkagi\u002Fsup.c#L947\u003C\u002Fp>\u003Cp>I made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Instead of using the ntdll.lib file (included after installing DDK), obtain NTAPI through ntdll\u003C\u002Fli>\u003Cli>Extract key code\u003C\u002Fli>\u003Cli>Fix bugs\u003C\u002Fli>\u003Cli>Add functionality to call the COM component IFileOperation for file copying\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code modifies the current process's PEB structure to deceive PSAPI into recognizing it as explorer.exe, then calls the COM component IFileOperation to achieve file copying\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>The current process is modified to explorer.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016707803_0_dfd4bf8021.jpeg\">\u003C\u002Fp>\u003Cp>File copying succeeded without triggering the UAC confirmation dialog, achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x05 Implementation Method 3: Calling the COM component IFileOperation via powershell.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First compile a COM component in C# to call IFileOperation for file copying, then invoke this COM component via PowerShell\u003C\u002Fp>\u003Ch3>1. Write COM component\u003C\u002Fh3>\u003Cp>Code reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Ftree\u002Fmaster\u002FBypass-UAC\u002FFileOperations\u002FFileOperations\u003C\u002Fp>\u003Cp>After successful compilation, generate FileOperation.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source project referenced by Ruben Boonen (b33f@FuzzySecurity):\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmlaily\u002FMSDNMagazine2007-.NET-Matters-IFileOperation-in-Windows-Vista\u003C\u002Fp>\u003Cp>He made modifications (such as changing class names) based on this, enabling PowerShell to directly call the COM component, which is a great feature\u003C\u002Fp>\u003Ch3>2. Call this COM component via PowerShell\u003C\u002Fh3>\u003Cp>There are two methods:\u003C\u002Fp>\u003Cp>(1) [System.Reflection.Assembly]::LoadFile($Path)\u003C\u002Fp>\u003Cp>Load the file directly\u003C\u002Fp>\u003Cp>(2) [Reflection.Assembly]::Load($bytes)\u003C\u002Fp>\u003Cp>Compress the file into a string stored in an array. Refer to Matthew Graeber's method, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2012\u002F12\u002Fin-memory-dll-loading.html\u003C\u002Fp>\u003Cp>Can directly output usable PowerShell code\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Comparison of the two methods was introduced in the previous article 'Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile'\u003C\u002Fp>\u003Cp>Complete implementation code for Method 3 can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Febbb8991a8a051b48c05ce676524a1ba787dbf0c\u002FBypass-UAC\u002FBypass-UAC.ps1#L1082\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>Executing PowerShell script, loading COM component IFileOperation. Since powershell.exe is a trusted process, no UAC confirmation dialog pops up, successfully achieving privilege escalation for file copying\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COM component IFileOperation is applicable from Win7 to Win10, so the privilege escalation file copying method is also usable\u003C\u002Fp>\u003Cp>For explorer.exe, loading high-privilege COM components does not trigger UAC dialog.\u003C\u002Fp>\u003Cp>This article has already implemented the method to simulate explorer.exe. So, are there other usable COM components? And what 'privilege escalation operations' can they accomplish?\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced three methods for privilege escalation file copying via COM component IFileOperation, organized and developed implementation code that can be used for direct testing\u003C\u002Fp>\u003Cp>Finally, thanks to Ruben Boonen (b33f@FuzzySecurity) for his help in my research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Analysis of Invoke-WScriptBypassUAC Exploitation in Empire', a method for unauthorized file copying was introduced. Under standard user permissions, wusa could be used to extract cab files into administrator-privileged folders, enabling further filename hijacking and UAC bypass.\u003C\u002Fp>\u003Cp>However, this functionality was removed in Windows 10. So, is there a more universal method?\u003C\u002Fp>\u003Cp>This article will introduce a method applicable from Windows 7 to Windows 10—using the COM component IFileOperation.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Principle\u003C\u002Fli>\u003Cli>Three Implementation Approaches\u003C\u002Fli>\u003Cli>Example Code\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from the workshop at Defcon 25, Ruben Boonen's \"UAC 0day, all day!\"\u003C\u002Fp>\u003Cp>PPT download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FDefCon25\u002Fblob\u002Fmaster\u002FDefCon25_UAC-0day-All-Day_v1.2.pdf\u003C\u002Fp>\u003Cp>Prerequisites for exploiting the COM component IFileOperation to copy files with elevated privileges:\u003C\u002Fp>\u003Cul>\u003Cli>Systems after Windows 7\u003C\u002Fli>\u003Cli>Trusted files in trusted paths (e.g., explorer.exe, powershell.exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, there are three implementation approaches:\u003C\u002Fp>\u003Ch3>1. DLL hijacking or DLL injection\u003C\u002Fh3>\u003Cp>Since trusted files in trusted paths are generally located in directories requiring administrator privileges, DLL hijacking is essentially impossible under normal user permissions.\u003C\u002Fp>\u003Cp>A feasible method is DLL injection.\u003C\u002Fp>\u003Cp>For example, explorer.exe can be subjected to DLL injection under normal user permissions.\u003C\u002Fp>\u003Ch3>2. Modify the PEB structure to deceive PSAPI and invoke the COM component IFileOperation\u003C\u002Fh3>\u003Cp>The COM component uses the Process Status API (PSAPI) to read the Commandline in the process's PEB structure to identify the processes they are running.\u003C\u002Fp>\u003Cp>If the process's Path is changed to a trusted file (e.g., explorer.exe), it can deceive PSAPI and invoke the COM component IFileOperation to achieve privileged file copying.\u003C\u002Fp>\u003Ch3>3. Directly calling COM component IFileOperation through trusted files\u003C\u002Fh3>\u003Cp>For example, powershell.exe is a trusted file and can directly call the COM component IFileOperation\u003C\u002Fp>\u003Ch2>0x03 Implementation Method 1: DLL injection into explorer.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The specific implementation is divided into the following two parts:\u003C\u002Fp>\u003Col>\u003Cli>Injecting the DLL into the process explorer.exe\u003C\u002Fli>\u003Cli>The DLL implements calling the COM component IFileOperation to copy files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>There is already a complete implementation code on GitHub, so you can refer to this project for analysis. The project address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhjc4869\u002FUacBypass\u003C\u002Fp>\u003Cp>(1) The project UacBypassTest implements DLL injection into the process explorer.exe\u003C\u002Fp>\u003Cp>Remove unnecessary functions and retain only the function of injecting UacBypass.dll into the process explorer.exe:\u003C\u002Fp>\u003Cp>Delete Line 58\u003C\u002Fp>\u003Cp>(2) The project UacBypass implements calling the COM component IFileOperation to copy files\u003C\u002Fp>\u003Cp>After compiling this project, the file UacBypass.dll is generated, which implements copying ntwdblib.dll from the same directory to C:\\windows\\System32\u003C\u002Fp>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Run UacBypassTest.exe to inject UacBypass.dll into the explorer.exe process, successfully achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x04 Implementation Method 2: Modify PEB structure, deceive PSAPI, call COM component IFileOperation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the UacBypass project, convert dll to exe, add header files, fix bugs, complete code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Achieved copying c:\\6\\ntwdblib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>\u003Cstrong>Code analysis:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for success is specifying the properties of this COM component (requires elevated privileges)\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fbb775799.aspx\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Property description:\u003C\u002Fp>\u003Cul>\u003Cli>FOF_NOCONFIRMATION: No confirmation dialog pops up\u003C\u002Fli>\u003Cli>FOF_SILENT: No dialog pops up\u003C\u002Fli>\u003Cli>FOFX_SHOWELEVATIONPROMPT: Elevation prompt required\u003C\u002Fli>\u003Cli>FOFX_NOCOPYHOOKS: Do not use copy hooks\u003C\u002Fli>\u003Cli>FOFX_REQUIREELEVATION: Default elevation required\u003C\u002Fli>\u003Cli>FOF_NOERRORUI: No error dialog on failure\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>Running the exe directly triggers a UAC confirmation dialog indicating insufficient permissions; if allowed, file copying can proceed\u003C\u002Fp>\u003Cp>Next, functionality to modify the PEB structure needs to be added to deceive PSAPI. The following locations must be modified:\u003C\u002Fp>\u003Cul>\u003Cli>ImagePathName in _RTL_USER_PROCESS_PARAMETERS\u003C\u002Fli>\u003Cli>FullDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003Cli>BaseDllName in _LDR_DATA_TABLE_ENTRY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CommandLine in _RTL_USER_PROCESS_PARAMETERS does not need modification. This attribute can be viewed via Process Explorer; for greater deception, it can optionally be altered\u003C\u002Fp>\u003Cp>Here, I referenced the implementation code of supMasqueradeProcess() in UACME at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002F143ead4db6b57a84478c9883023fbe5d64ac277b\u002FSource\u002FAkagi\u002Fsup.c#L947\u003C\u002Fp>\u003Cp>I made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Instead of using the ntdll.lib file (included after installing DDK), obtain NTAPI through ntdll\u003C\u002Fli>\u003Cli>Extract key code\u003C\u002Fli>\u003Cli>Fix bugs\u003C\u002Fli>\u003Cli>Add functionality to call the COM component IFileOperation for file copying\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For more details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code modifies the current process's PEB structure to deceive PSAPI into recognizing it as explorer.exe, then calls the COM component IFileOperation to achieve file copying\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>The current process is modified to explorer.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016707803_0_dfd4bf8021-1.jpeg\">\u003C\u002Fp>\u003Cp>File copying succeeded without triggering the UAC confirmation dialog, achieving unauthorized file copying\u003C\u002Fp>\u003Ch2>0x05 Implementation Method 3: Calling the COM component IFileOperation via powershell.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First compile a COM component in C# to call IFileOperation for file copying, then invoke this COM component via PowerShell\u003C\u002Fp>\u003Ch3>1. Write COM component\u003C\u002Fh3>\u003Cp>Code reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Ftree\u002Fmaster\u002FBypass-UAC\u002FFileOperations\u002FFileOperations\u003C\u002Fp>\u003Cp>After successful compilation, generate FileOperation.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source project referenced by Ruben Boonen (b33f@FuzzySecurity):\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmlaily\u002FMSDNMagazine2007-.NET-Matters-IFileOperation-in-Windows-Vista\u003C\u002Fp>\u003Cp>He made modifications (such as changing class names) based on this, enabling PowerShell to directly call the COM component, which is a great feature\u003C\u002Fp>\u003Ch3>2. Call this COM component via PowerShell\u003C\u002Fh3>\u003Cp>There are two methods:\u003C\u002Fp>\u003Cp>(1) [System.Reflection.Assembly]::LoadFile($Path)\u003C\u002Fp>\u003Cp>Load the file directly\u003C\u002Fp>\u003Cp>(2) [Reflection.Assembly]::Load($bytes)\u003C\u002Fp>\u003Cp>Compress the file into a string stored in an array. Refer to Matthew Graeber's method, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2012\u002F12\u002Fin-memory-dll-loading.html\u003C\u002Fp>\u003Cp>Can directly output usable PowerShell code\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Comparison of the two methods was introduced in the previous article 'Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile'\u003C\u002Fp>\u003Cp>Complete implementation code for Method 3 can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Febbb8991a8a051b48c05ce676524a1ba787dbf0c\u002FBypass-UAC\u002FBypass-UAC.ps1#L1082\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>Executing PowerShell script, loading COM component IFileOperation. Since powershell.exe is a trusted process, no UAC confirmation dialog pops up, successfully achieving privilege escalation for file copying\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>COM component IFileOperation is applicable from Win7 to Win10, so the privilege escalation file copying method is also usable\u003C\u002Fp>\u003Cp>For explorer.exe, loading high-privilege COM components does not trigger UAC dialog.\u003C\u002Fp>\u003Cp>This article has already implemented the method to simulate explorer.exe. So, are there other usable COM components? And what 'privilege escalation operations' can they accomplish?\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced three methods for privilege escalation file copying via COM component IFileOperation, organized and developed implementation code that can be used for direct testing\u003C\u002Fp>\u003Cp>Finally, thanks to Ruben Boonen (b33f@FuzzySecurity) for his help in my research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",31,"Onedaysec",5,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Unauthorized File Copy via COM IFileOperation: UAC Bypass Methods","UAC bypass, IFileOperation COM, unauthorized file copy, Windows security, DLL injection, PEB modification, privilege escalation, Windows 7 to 10, exploit techniques, trusted files",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1190,1189,1187,1186,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.004Z","2026-07-23T16:02:39.381Z","draft","2026-07-23T16:17:16.135Z"]