Insecure GUI Application Windows Privilege Promotion


Some of the words

Elevated privileges in application to try here, part of the GUI application to current higher outside of the current user permissions to access certain services, for our right to provide some convenience, when the terminal can't through the access permissions, spend more time looking for unsafe configuration GUI programs of this type are very much worth it

Actual use

Here to notepad in Win10 use as a case, to illustrate, here to log in to the system as an administrator, check personal permissions, only 5 permissions information as follows

image-20211106172808300

Try adding a user to verify the current user's permissions. It's simple. The current user does not have higher permissions to add users

image-20211106172858371

Note This section uses Notepad as an example to describe how to run an unsafe configuration operation as an administrator

image-20211106172957533

After further exploring the function of Notepad, it can be known that you can enter the resource manager to select the file and open the file for us. Note that because we have selected the permission to run as administrator above, if you can open CMD or run other executable programs, you will run the file with high permission. At this time we can try to open the file resource manager runs within our target

image-20211106173218068

Progress to view its user permissions

image-20211106173258852

I am sure you know how to continue to use it

image-20211106173429767


Author: Yangsir
Reprint policy: All articles in this blog are used except for special statements CC BY 4.0 reprint policy. If reproduced, please indicate source Yangsir !
  TOC