You are auditing a machine and find a folder with 'AlwaysInstallElevated' enabled in the registry for both HKLM and HKCU. Which TWO actions allow you to achieve privilege escalation?
Trap 1: Directly modify the kernel memory to escalate the current process.
Modifying kernel memory is an extremely complex and dangerous task that could crash the system. AlwaysInstallElevated is a high-level configuration flaw that does not require kernel-level manipulation to exploit. Using such an approach is unnecessary and significantly increases the risk of detection or system instability.
Trap 2: Delete the HKLM registry key to disable the elevation.
Deleting the registry key would remove the vulnerability, which is the opposite of the goal. The objective of privilege escalation is to leverage existing misconfigurations to gain access, not to perform system remediation or clean up the environment for the target system administrators.
Trap 3: Use the 'runas' command to switch to the SYSTEM user.
The 'runas' command requires knowledge of the target user's password. Since you are performing privilege escalation, you do not have the credentials for the SYSTEM account. AlwaysInstallElevated allows you to run code as SYSTEM without needing a password, rendering the 'runas' command irrelevant for this specific exploitation vector.
- A
Create an MSI installer that executes a reverse shell.
Since the system is configured to elevate installations, an MSI package containing a custom action that runs a reverse shell will execute with SYSTEM privileges. This is the primary method of exploiting this misconfiguration, allowing the attacker to bypass standard user restrictions and establish a high-privilege connection.
- B
Directly modify the kernel memory to escalate the current process.
Why it fails: Modifying kernel memory is an extremely complex and dangerous task that could crash the system. AlwaysInstallElevated is a high-level configuration flaw that does not require kernel-level manipulation to exploit. Using such an approach is unnecessary and significantly increases the risk of detection or system instability.
- C
Execute the MSI package using the msiexec /quiet /qn /i command.
The /quiet and /qn flags ensure the installation runs without user interaction, which is necessary when deploying a payload from the command line. Coupled with AlwaysInstallElevated, this command triggers the installation process, which elevates the embedded malicious code to run under the context of the SYSTEM account.
- D
Delete the HKLM registry key to disable the elevation.
Why it fails: Deleting the registry key would remove the vulnerability, which is the opposite of the goal. The objective of privilege escalation is to leverage existing misconfigurations to gain access, not to perform system remediation or clean up the environment for the target system administrators.
- E
Use the 'runas' command to switch to the SYSTEM user.
Why it fails: The 'runas' command requires knowledge of the target user's password. Since you are performing privilege escalation, you do not have the credentials for the SYSTEM account. AlwaysInstallElevated allows you to run code as SYSTEM without needing a password, rendering the 'runas' command irrelevant for this specific exploitation vector.