Windows Escalate UAC Protection Bypass
Posted by deepcore on November 19, 2019 – 3:10 pm
This Metasploit module will bypass Windows UAC by hijacking a special key in the Registry under the current user hive, and inserting a custom command that will get invoked when Windows backup and restore is launched. It will spawn a second shell that has the UAC flag turned off. This module modifies a registry key, but cleans up the key once the payload has been invoked.
Post a reply
You must be logged in to post a comment.