GPEN Domain Escalation and Persistence Practice Question
During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
⚠ Common exam trap
Candidates often try to modify the existing service binary. They forget that the vulnerability relies on the path resolution order, requiring the placement of a new file, not modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place a malicious binary at the first detected space-delimited path segment.
Unquoted service paths exist when the service binary path contains spaces and lacks quotes. Windows interprets the path incorrectly, searching for intermediate executables. Placing a malicious binary at the identified path allows it to execute with SYSTEM privileges upon service restart. This technique is critical for privilege escalation as it exploits inherent Windows path resolution logic, often bypassing standard user restrictions if the directory has weak permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Overwrite the existing service executable with a custom payload.
Why it's wrong here
Overwriting the actual binary requires administrative permissions that you do not yet possess. If you had permissions to modify the existing binary, you would already have achieved execution, rendering the unquoted path vulnerability irrelevant. This action is usually blocked by standard NTFS access control lists on system directories.
- ✗
Modify the service configuration using the sc config command.
Why it's wrong here
Changing the service configuration via sc config requires elevated administrative privileges. Since the goal is to escalate privileges, you cannot rely on commands that already require the level of access you are attempting to obtain. This approach is ineffective for a standard user account seeking privilege escalation.
- ✓
Place a malicious binary at the first detected space-delimited path segment.
Why this is correct
Windows attempts to execute the path segment before the space if no quotes are present. By placing a malicious executable at that specific location with the appropriate name, the service manager will execute your file instead of the intended one, running your code with the service's high-privilege context.
- ✗
Inject a DLL into the running service process memory space.
Why it's wrong here
Process injection via DLL injection typically requires administrative rights or SeDebugPrivilege to attach to a high-privilege service process. While effective for persistence or credential dumping, it does not leverage the unquoted service path vulnerability itself and is generally restricted for unprivileged users on modern Windows operating systems.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.