When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?
The Windows Installer policy check evaluates both the current user hive and the local machine hive before executing installations. Setting this specific registry key to 1 in the user hive informs the operating system that packages run by this user should receive elevated rights.
Why this answer
AlwaysInstallElevated allows low-privileged users to install malicious MSI packages with elevated NT AUTHORITY\SYSTEM privileges. However, exploitation requires both registry hive keys to be properly configured to enabled values. Verifying both keys ensures the Windows Installer service honors the elevated installation flag for all packages regardless of user context.
Exam trap
Candidates frequently check only the HKLM key, forgetting that the HKCU policy must also be enabled. Both keys are required for the Windows Installer to honor the elevated privilege flag.