Courseiva

CCNA Windows Privilege Escalation Questions

24 questions · Windows Privilege Escalation · All types, answers revealed

1
Multi-Selecthard

When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?

Select 2 answers
A.The AlwaysInstallElevated value must be set to 1 in HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer.
B.The AlwaysInstallElevated value must be set to 1 in HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer.
C.The local security policy must allow standard users to bypass User Account Control prompts via group policy objects.
D.The target user account must possess local Administrator group membership prior to executing the malicious MSI package.
E.The Task Scheduler service must be configured to permit interactive logons for disabled service accounts.
AnswersA, B

The Windows Installer policy check evaluates both the current user hive and the local machine hive before executing installations. Setting this specific registry key to 1 in the user hive informs the operating system that packages run by this user should receive elevated rights.

Why this answer

AlwaysInstallElevated allows low-privileged users to install malicious MSI packages with elevated NT AUTHORITY\SYSTEM privileges. However, exploitation requires both registry hive keys to be properly configured to enabled values. Verifying both keys ensures the Windows Installer service honors the elevated installation flag for all packages regardless of user context.

Exam trap

Candidates frequently check only the HKLM key, forgetting that the HKCU policy must also be enabled. Both keys are required for the Windows Installer to honor the elevated privilege flag.

2
Multi-Selecthard

A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?

Select 2 answers
A.The task is configured to run under the context of the SYSTEM account or a member of the Administrators group.
B.The task must have a trigger set to 'At log on' for any user on the system.
C.The attacker has permissions to modify the binary or script executed by the task, or can rewrite the task's action path.
D.The 'Hidden' attribute must be enabled in the task settings to bypass Windows Defender detection.
E.The task must be part of the default Windows installation rather than a third-party application.
AnswersA, C

Privilege escalation requires moving from a lower privilege level to a higher one. If the task runs as the current low-privilege user, executing code through it provides no elevation. Targeting tasks that run as SYSTEM ensures that once the execution path is hijacked, the resulting shell or command will possess maximum system authority.

Why this answer

Scheduled tasks are a common persistence and escalation vector. For escalation, the task must execute with higher privileges than the current user, typically as SYSTEM or an Administrator. Additionally, the attacker must have the ability to influence what the task executes, either by modifying the executable file, a script it calls, or the task configuration itself to point to a malicious file.

Exam trap

A common mistake is assuming that any task running as SYSTEM is exploitable. Without the ability to modify the action or the underlying file, the task is secure regardless of its privileges.

3
MCQhard

Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?

A.The service is immune to DLL hijacking.
B.The service cannot be exploited.
C.The service is still fully capable of performing administrative actions.
D.The service only runs when a user is logged in.
AnswerC

The 'LocalSystem' account is inherently privileged. Whether a service is 'interactive' or not only dictates its ability to show a desktop window. The underlying privileges remain the same, meaning an attacker gaining control of the service process still gains full administrative control over the host.

Why this answer

Even without the 'Interactive' flag, a service running as 'LocalSystem' has the highest possible privileges on the local machine. The flag only determines if the service can display a GUI to the logged-in user. Attackers can still interact with these services via command-line exploits or by injecting code into them, making the 'Interactive' flag irrelevant for determining the security risk of the service account.

Exam trap

Candidates incorrectly assume that a service lacking the 'Interactive' flag is less privileged or cannot be exploited, failing to realize it still runs with full LocalSystem administrative rights.

4
MCQeasy

During a penetration test on a Windows Server 2019 host, you obtain a low-privileged shell as user 'webuser'. You run 'whoami /priv' and observe that the account has SeImpersonatePrivilege enabled. Which exploitation technique is most directly applicable?

A.Schedule a task to run as SYSTEM using schtasks with the /RU SYSTEM flag.
B.Use a token impersonation attack such as JuicyPotato or PrintSpoofer to impersonate a SYSTEM token.
C.Modify a service binary that runs as SYSTEM to execute a reverse shell.
D.Extract password hashes from the SAM database using Mimikatz and pass-the-hash.
AnswerB

SeImpersonatePrivilege allows a process to impersonate a token, and tools like JuicyPotato or PrintSpoofer abuse this by coercing a privileged service to authenticate, then capturing and impersonating its token. This directly leverages the privilege to escalate to SYSTEM without needing to modify files or registry keys.

Why this answer

SeImpersonatePrivilege permits a process to impersonate another user's token. Attackers exploit this by forcing a privileged service to authenticate to a controlled endpoint, then impersonating its token to gain SYSTEM-level access. Tools like JuicyPotato, RoguePotato, or PrintSpoofer automate this.

The other options require permissions not granted by this privilege, such as file write or administrative task creation.

Exam trap

The trap here is assuming that SeImpersonatePrivilege alone allows direct token theft from any process, when it actually requires coercing a privileged service to authenticate first.

5
MCQhard

You have obtained a low-privileged shell on a Windows Server 2016 machine. While enumerating, you notice that the 'SeImpersonatePrivilege' is enabled for your user account. You also find that the machine is running a service with a named pipe '\\.\pipe\svcctl' that is accessible. Which tool is specifically designed to exploit this privilege to escalate to SYSTEM?

A.WinPEAS
B.JuicyPotato
C.PowerUp
D.Mimikatz
AnswerB

JuicyPotato exploits SeImpersonatePrivilege by tricking a privileged process into connecting to a malicious named pipe, then impersonating its token. It is specifically designed for Windows systems where SeImpersonate is enabled. The tool leverages COM object hijacking and is effective on many Windows versions, including Server 2016. It directly addresses the scenario.

Why this answer

JuicyPotato is designed to exploit SeImpersonatePrivilege by coercing a privileged process to authenticate to a malicious named pipe, then impersonating its token. This allows escalation to SYSTEM. PowerUp and WinPEAS are enumeration tools, and Mimikatz is for credential dumping, not privilege escalation via token impersonation.

Exam trap

The trap here is confusing enumeration tools like WinPEAS or PowerUp with exploitation tools that actually leverage SeImpersonatePrivilege.

6
MCQmedium

You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?

A.Restart the service immediately to trigger a buffer overflow.
B.Overwrite the existing service executable with your payload.
C.Place a malicious binary at a location in the unquoted path that the user can write to.
D.Modify the Windows Registry to point the service to a new location.
AnswerC

When a path is unquoted, Windows searches for the executable by adding .exe to parts of the string. If the path is C:\Program Files\My App\service.exe, Windows checks C:\Program.exe first. If you place a malicious binary there, the system will execute it as SYSTEM when the service starts.

Why this answer

Unquoted service paths are vulnerable because Windows attempts to resolve the path by interpreting spaces as delimiters. By placing a malicious executable at an intermediate folder in the path, the service manager executes your binary with SYSTEM privileges upon restart. Identifying and exploiting these paths is a foundational skill for post-exploitation, allowing attackers to elevate from standard user to the highest possible integrity level without needing complex kernel exploits.

Exam trap

Candidates often try to modify the entire service path or rewrite system files instead of exploiting the space-delimited path resolution logic by dropping a binary in an intermediate writable folder.

7
Multi-Selecthard

During a Windows privilege escalation assessment, you encounter a service with an unquoted service path: 'C:\Program Files\Vulnerable Service\service.exe'. The service runs as LocalSystem. Which TWO conditions must be true for you to successfully exploit this unquoted service path? (Choose two.)

Select 2 answers
A.The service must be configured to start automatically.
B.You must be able to restart the service or trigger a system reboot.
C.You must have write permissions to a directory that appears earlier in the path.
D.The service binary must be missing from its intended location.
E.You must have administrative privileges to exploit the service.
AnswersB, C

After placing the malicious binary, the service must execute it. This requires the service to start or restart. If you cannot restart the service yourself, waiting for a system reboot may also trigger it if the service starts automatically. Without execution, the exploit does not escalate privileges.

Why this answer

To exploit an unquoted service path, you need write access to a directory that Windows searches before the legitimate binary, and you must be able to cause the service to execute (by restarting it or rebooting). The other conditions are not required: the service can be manual, the binary can be present, and you do not need admin rights.

Exam trap

The trap here is thinking the service must be automatic or the binary missing; actually, write access to an earlier directory and the ability to trigger execution are the critical factors.

8
MCQmedium

During enumeration of a Windows host, you run `whoami /priv` and see that the current user has SeImpersonatePrivilege enabled. You have also uploaded a custom executable to C:\Windows\Temp. Which privilege escalation technique is most directly applicable in this situation?

A.Exploit the SeImpersonatePrivilege using a tool such as PrintSpoofer or RoguePotato to impersonate a SYSTEM token.
B.Dump LSASS memory using a tool like Mimikatz to extract plaintext credentials and then use them to log in as an administrator.
C.Modify the service binary path of a running service to point to your uploaded executable and restart the service.
D.Use `runas /savecred` to execute a command as the local administrator without knowing the password.
AnswerA

SeImpersonatePrivilege allows a process to impersonate a token, and tools like PrintSpoofer or RoguePotato abuse this by coercing a privileged service to authenticate, then capturing and impersonating its token. This is a well-known privilege escalation path when the privilege is enabled, and it directly applies here.

Why this answer

SeImpersonatePrivilege permits a process to impersonate another user's token, and tools like PrintSpoofer exploit this by tricking a privileged service into connecting to a controlled endpoint, then impersonating the resulting token. This is a direct escalation path when the privilege is enabled, making it the most applicable technique here.

Exam trap

The trap here is assuming that SeImpersonatePrivilege alone allows direct code execution as SYSTEM without the need for token coercion techniques.

9
MCQeasy

What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?

A.To bypass Windows Firewall rules.
B.To identify files and services with weak permissions.
C.To dump the SAM database for password hashes.
D.To automate the deployment of kernel exploits.
AnswerB

Accesschk is specifically designed to display the effective permissions for a user or group on various system objects. It is the industry-standard tool for finding files, services, or registry keys that are improperly secured, allowing for targeted privilege escalation attempts on a compromised system.

Why this answer

Accesschk is a powerful tool from the Sysinternals suite used to check the permissions of files, directories, registry keys, and services. In privilege escalation, it allows an attacker to quickly find misconfigured resources that the current user can modify. By identifying these 'weak' permissions, the attacker can pinpoint specific targets for exploitation, such as replacing a service binary or modifying a sensitive script.

Exam trap

Candidates often confuse accesschk with credential dumping tools or general vulnerability scanners, failing to recognize its specific utility for auditing resource permissions.

10
MCQmedium

You have a low-privileged shell on a Windows 10 workstation and discover that the folder 'C:\ProgramData\Updater' has weak permissions: the 'Users' group has 'Write' and 'Modify' rights. A scheduled task runs 'C:\ProgramData\Updater\update.exe' every hour as SYSTEM. What is the most reliable way to escalate privileges?

A.Run a DLL hijacking attack by placing a malicious DLL in the folder and restarting the service.
B.Create a new scheduled task that runs as SYSTEM using schtasks /create /ru SYSTEM.
C.Use icacls to grant yourself Full Control on the folder, then modify the task's XML definition.
D.Replace update.exe with a malicious executable that adds your user to the Administrators group.
AnswerD

Since the Users group can modify files in that directory, you can overwrite update.exe with a payload. When the scheduled task runs as SYSTEM, your payload executes with SYSTEM privileges, allowing you to add your user to the Administrators group. This is a classic writable directory privilege escalation.

Why this answer

A writable directory containing a scheduled task's executable allows a low-privileged user to replace that executable with a malicious payload. When the task runs as SYSTEM, the payload executes with elevated privileges. This technique is straightforward and does not require additional vulnerabilities.

The other options either require administrative rights or rely on unconfirmed application behavior.

Exam trap

The trap here is overcomplicating the attack by assuming you need to modify the task itself, when simply replacing the executable is sufficient and more reliable.

11
MCQmedium

Refer to the exhibit. What is the primary vulnerability shown here?

A.The task is not running, so it is secure.
B.The task executes a batch file that may be writable by users.
C.The task name '\SystemTask' is too generic.
D.Scheduled tasks cannot be used for privilege escalation.
AnswerB

Scheduled tasks that execute scripts are vulnerable if the script file is writable by the current user. Since the task runs with SYSTEM privileges, hijacking the script allows the user to execute arbitrary commands with those same elevated privileges, facilitating a direct path to system-wide compromise.

Why this answer

The scheduled task '\SystemTask' runs as 'SYSTEM' and executes 'C:\scripts\run.bat'. If a standard user has write access to 'run.bat' or the directory 'C:\scripts', they can modify the script to run any command. Since the task runs as SYSTEM, the modified command will also run as SYSTEM, leading to a simple and effective privilege escalation path via scheduled task hijacking.

Exam trap

Candidates often overthink the task configuration and look for complex buffer overflows or registry issues, missing the simple, common misconfiguration of a writable batch file executed by a system task.

12
MCQmedium

You have compromised a Windows host and obtained credentials for a low-privileged domain user. You discover that this user has 'GenericWrite' permissions on a computer object in Active Directory. Which attack technique can you use to escalate privileges on that computer?

A.Perform a Kerberoasting attack to extract service account hashes.
B.Use Resource-Based Constrained Delegation (RBCD) by modifying the computer's msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
C.Exploit an unquoted service path on the target computer.
D.Conduct a DCSync attack to replicate domain controller hashes.
AnswerB

GenericWrite on a computer object allows modification of its attributes, including msDS-AllowedToActOnBehalfOfOtherIdentity. By setting this attribute to include a controlled account, you can configure RBCD, enabling that account to impersonate any user to the target computer, effectively escalating to administrative access on that machine.

Why this answer

GenericWrite on a computer object permits modification of its attributes. Setting msDS-AllowedToActOnBehalfOfOtherIdentity enables Resource-Based Constrained Delegation, allowing a controlled account to impersonate users to that computer. This can lead to full compromise of the target machine.

The other techniques require different permissions or local access, making them ineffective here.

Exam trap

The trap here is assuming that GenericWrite on a computer object directly grants administrative access, when it actually enables attribute modification that can be leveraged for RBCD.

13
MCQmedium

You have a low-privileged shell on a Windows Server 2016 host and run `whoami /priv`. The output shows `SeImpersonatePrivilege` enabled. You also notice that the `Print Spooler` service is running. Which technique would most directly allow you to escalate to NT AUTHORITY\SYSTEM?

A.Exploit an unquoted service path in the Print Spooler service binary path to plant a malicious executable.
B.Use `RottenPotato` to relay NTLM authentication from the spooler to an attacker-controlled SMB server and capture the SYSTEM token.
C.Use the `PrintSpoofer` tool to coerce the Print Spooler service into authenticating to a named pipe under your control, then impersonate the SYSTEM token.
D.Abuse the `SeBackupPrivilege` to copy the SAM and SYSTEM registry hives, then extract local password hashes offline.
AnswerC

`PrintSpoofer` leverages the Print Spooler service to force a SYSTEM-level authentication to a named pipe you create. With `SeImpersonatePrivilege`, you can capture and impersonate that token, gaining SYSTEM. This is a direct and reliable escalation when the spooler is running and your account holds the privilege.

Why this answer

When `SeImpersonatePrivilege` is enabled and the Print Spooler service is running, coercing a SYSTEM authentication to a controlled named pipe allows token impersonation. `PrintSpoofer` automates this by triggering the spooler to connect to a malicious pipe, then impersonating the resulting token. This yields a direct SYSTEM shell without needing additional misconfigurations.

Exam trap

The trap here is assuming that any privilege escalation requires a service misconfiguration or weak file permissions, overlooking that `SeImpersonatePrivilege` alone can be abused via token coercion techniques like `PrintSpoofer`.

14
MCQmedium

During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?

A.Modify the Windows Registry ImagePath entry directly using standard user credentials to append your custom payload path.
B.Replace the existing service executable file directly inside the protected system folder to hijack execution upon the next reboot.
C.Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.
D.Send a malformed buffer overflow payload directly to the service network port to achieve remote code execution as Local System.
AnswerC

Overly permissive DACLs on the parent folder allow standard users to create a malicious executable that matches the first space-separated token of the path. When the service starts, Windows executes this malicious binary instead of the intended program because quotes are missing.

Why this answer

Placing a malicious executable with a name matching the fragmented path segment allows you to hijack the service binary resolution process when the service restarts. Windows searches for spaces sequentially from left to right, executing your payload with Local System privileges. This technique is a fundamental Windows privilege escalation vector taught in the PEN-200 curriculum.

Exam trap

Candidates often try to replace the original service executable. However, the exploit relies on creating a new, malicious executable that matches the fragmented path segment to hijack the resolution process.

15
MCQmedium

Refer to the exhibit. What can you conclude about the security of this service binary?

A.The service is vulnerable to a DLL hijacking attack.
B.The binary can be replaced by any local user to achieve privilege escalation.
C.The service is secure because only SYSTEM and Administrators have full access.
D.The service cannot be stopped by a standard user.
AnswerB

The '(M)' permission granted to BUILTIN\Users allows any standard user to write to, modify, or delete the file. By replacing the service executable with a malicious payload, the user can ensure that the next time the service starts, the malicious code executes with SYSTEM privileges.

Why this answer

The icacls output shows that 'BUILTIN\Users' has '(M)' or Modify permissions on the binary. This means a low-privileged user can replace the legitimate service executable with a malicious one. Because services run as SYSTEM, replacing this file allows for immediate privilege escalation upon the next service restart.

This is a common misconfiguration where excessive folder or file permissions enable attackers to gain total control over the host.

Exam trap

Candidates mistakenly believe that Read permissions are sufficient to compromise a binary, overlooking the requirement for Modify or Write access to replace the file.

16
MCQhard

You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?

A.Exploiting the unquoted service path.
B.DLL Hijacking.
C.Modify the service binary directly.
D.Overwriting the service configuration file.
AnswerB

When an application loads a DLL, it searches the application directory first. If you have write access to that directory, you can place a malicious DLL with a matching name. The application will load it instead of the system version, executing your code under the service's context.

Why this answer

If the binary is read-only but the directory is writable, you may be able to perform DLL hijacking. Windows applications often look for DLLs in the application directory before searching system folders. By placing a malicious DLL with the same name as a dependency into the application's folder, you can force the application to load your code when it starts, gaining SYSTEM privileges.

Exam trap

Candidates attempt to replace the read-only service executable directly, forgetting that directory-level write access enables alternative vectors like DLL hijacking.

17
MCQhard

You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?

A.Leverage the setting to bypass UAC and run any executable as an administrator without an MSI package.
B.Create a malicious MSI package and execute it with `msiexec /quiet /qn /i malicious.msi` to run with SYSTEM privileges.
C.Use `reg add` to modify the service binary path of a running service to point to a malicious executable.
D.Extract the MSI to a writable directory and replace a DLL to achieve privilege escalation.
AnswerB

When AlwaysInstallElevated is enabled in both HKLM and HKCU, any MSI package installed by the user runs with elevated (SYSTEM) privileges. You can generate a malicious MSI that executes a command, for example adding a user to the Administrators group, and then install it using `msiexec` with quiet flags to avoid user interaction.

Why this answer

With AlwaysInstallElevated enabled in both registry hives, any MSI package installed by a user runs with SYSTEM privileges. The most direct exploitation is to create a malicious MSI that performs a privileged action, such as adding a user to the Administrators group, and then install it using `msiexec`. This leverages the misconfiguration exactly as designed.

Exam trap

The trap here is thinking that AlwaysInstallElevated allows arbitrary executables to run elevated, when it specifically applies to MSI packages.

18
MCQmedium

You are on a Windows 10 machine and discover that the folder 'C:\Temp' has permissions: BUILTIN\Users:(F). You also notice that a scheduled task runs every hour, executing 'C:\Temp\cleanup.exe' as SYSTEM. However, cleanup.exe does not exist in the folder. What is the most effective way to escalate privileges?

A.Use icacls to change permissions on the scheduled task file.
B.Create a new scheduled task that runs as SYSTEM.
C.Modify the scheduled task to run a different command using schtasks.
D.Place a malicious cleanup.exe in C:\Temp and wait for the scheduled task to run.
AnswerD

Since the scheduled task runs cleanup.exe as SYSTEM and the folder is writable by Users, you can create a malicious executable named cleanup.exe. When the task triggers, it will execute your payload with SYSTEM privileges. This is a straightforward privilege escalation via a missing binary in a writable directory.

Why this answer

The scheduled task runs a missing executable from a writable directory as SYSTEM. By placing a malicious cleanup.exe in C:\Temp, you ensure that the task executes your code with SYSTEM privileges. This is a classic privilege escalation via weak folder permissions and scheduled tasks.

Exam trap

The trap here is overlooking that the task runs a missing binary and focusing on modifying the task itself, which requires higher privileges.

19
MCQmedium

When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?

A.To refresh the file system cache.
B.To trigger the execution of the new binary.
C.To bypass the Windows Service integrity check.
D.To allow the service to read the new configuration.
AnswerB

The Service Control Manager only executes the binary when the service is started. Replacing the file does not affect the currently running process. A restart is required to stop the original binary and initiate the new one, which allows the attacker's code to run as the service user.

Why this answer

Services run as long-lived processes. When the service starts, the binary is loaded into memory and executed. If you replace the binary while the service is running, the old process remains active.

Restarting the service forces the Service Control Manager to stop the original process and start the new, modified binary, thereby executing your malicious code in the process space of the service.

Exam trap

Candidates assume replacing a binary on disk immediately changes the running process behavior without realizing the old instance remains loaded in memory.

20
MCQmedium

You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?

A.Replace updater.exe and wait for the system to reboot, as services are automatically started on boot.
B.Replace updater.exe and then use `schtasks /run /tn <servicename>` to trigger the service.
C.Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.
D.Replace updater.exe and then use `wmic service where name='<servicename>' call startservice`.
AnswerC

The service executable is run with SYSTEM privileges. By replacing the binary and starting the service, your malicious code executes as SYSTEM. Since the service is stopped, you can overwrite the file and then start it. This is a direct and reliable method.

Why this answer

When a service binary is in a writable directory, replacing it with a malicious executable and then starting the service will run the payload as SYSTEM. Because the service is stopped, you can overwrite the file without issues. Using `sc start` is the direct way to trigger execution.

Waiting for a reboot is uncertain, and schtasks is for scheduled tasks, not services.

Exam trap

The trap here is overcomplicating the service start method or assuming a reboot is necessary, when simply starting the service with `sc start` is sufficient and reliable.

21
MCQmedium

An attacker gains a low-privilege shell on a Windows 10 machine and discovers a third-party service named 'DataSync'. The attacker notes that the service runs as SYSTEM and they have 'FILE_WRITE_DATA' permissions on the service executable 'C:\Program Files\DataSync\sync.exe'. Which action is the most direct method to escalate privileges to SYSTEM?

A.Place a malicious DLL named 'sync.dll' in the 'C:\Windows\System32' directory to intercept calls.
B.Stop the service, replace 'sync.exe' with a malicious payload, and restart the service.
C.Modify the service configuration using 'sc config' to point to a different malicious executable.
D.Create a new service with the same name in the 'HKCU' registry hive to override the system service.
AnswerB

This is the most direct path to escalation when 'FILE_WRITE_DATA' is available. By replacing the service binary, the attacker ensures their code runs with the service's privileges. If the attacker has the rights to stop and start the service, they can trigger the payload execution immediately without needing a full system reboot.

Why this answer

Service binary hijacking is a powerful technique where an attacker replaces a legitimate executable with a malicious one. Since the service runs as SYSTEM, the replaced binary will execute with those high privileges upon the next service start. This method is often more reliable than DLL hijacking because it directly controls the primary execution flow of the service, provided the attacker can restart the service or wait for a system reboot.

Exam trap

Candidates often confuse binary hijacking with DLL hijacking or unquoted service paths. They might look for missing quotes or library search orders instead of checking direct file permissions on the primary executable itself.

22
MCQmedium

You are attempting to escalate privileges on a Windows target and decide to exploit unquoted service paths. You find a service with the binary path `C:\Program Files\My App\service.exe` and the service is running as LocalSystem. Which condition must be true for this unquoted path to be exploitable?

A.The service must be configured to run as a domain user with a weak password that can be cracked.
B.A directory like `C:\Program.exe` or `C:\Program Files\My.exe` must be writable by your user, and the service must restart.
C.The service must have the `SeImpersonatePrivilege` enabled for the LocalSystem account.
D.The directory `C:\Program Files\My App` must have Modify permissions for the Everyone group.
AnswerB

Unquoted service paths are exploited by placing a malicious executable in a directory that Windows will search before reaching the intended binary. For the path `C:\Program Files\My App\service.exe`, Windows will try `C:\Program.exe`, then `C:\Program Files\My.exe`, and so on. If any of those locations are writable and the service restarts, your executable runs as LocalSystem.

Why this answer

For an unquoted service path to be exploitable, a writable directory must exist in the search order before the intended executable, such as `C:\Program.exe` or `C:\Program Files\My.exe`. When the service starts, Windows will execute the first found executable from that path. If you can place a malicious binary in a writable location and the service restarts, you gain code execution as the service account.

Exam trap

The trap here is assuming that write access to the service's own directory is required, when actually the vulnerability lies in writable parent directories due to missing quotes.

23
MCQmedium

During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?

A.Use 'certutil' to download and execute a portable executable (EXE) directly.
B.Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.
C.Modify the 'AlwaysInstallElevated' key in HKCU to point to a malicious script instead of '1'.
D.Inject a malicious DLL into the 'msiexec.exe' process while it is running.
AnswerB

This is the standard method for exploiting AlwaysInstallElevated. The 'msiexec' utility processes the MSI file, and because the policy is enabled, the Windows Installer service executes the internal scripts or binaries of the MSI as SYSTEM. The flags '/quiet' and '/qn' ensure the installation happens in the background without user interaction.

Why this answer

The AlwaysInstallElevated policy is a specific Windows feature that allows non-privileged users to run Windows Installer (MSI) packages with SYSTEM privileges. For this to work, the policy must be enabled in both the machine (HKLM) and user (HKCU) registry hives. Attackers can exploit this by crafting a malicious MSI file that executes a command, such as adding a user or opening a reverse shell.

Exam trap

Candidates often forget that BOTH registry keys must be set to 1. If only one is set, the installation will not run with elevated privileges, and the exploit will fail silently or return an error.

24
MCQmedium

Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?

A.To install a persistent backdoor on the system.
B.To perform automated enumeration for privilege escalation.
C.To escalate privileges to SYSTEM directly.
D.To exfiltrate sensitive files from the system.
AnswerB

Scripts like PowerUp are designed to search for common misconfigurations that lead to privilege escalation. Executing such scripts from a remote server is a standard technique to quickly identify escalation paths without leaving traces on the local file system, which helps maintain operational security during an engagement.

Why this answer

This command downloads and executes a PowerShell script directly into memory from a remote server. This is a common technique for running automated enumeration scripts like PowerUp or WinPEAS without writing them to the disk. By executing in memory, the attacker minimizes their footprint on the host system, avoiding detection by file-based signature scanning while gathering information about potential escalation vectors.

Exam trap

Candidates often assume this command is for persistence or data exfiltration. They miss that the primary goal in privilege escalation is automated enumeration to identify misconfigurations before manual exploitation begins.

Ready to test yourself?

Try a timed practice session using only Windows Privilege Escalation questions.