3 ms·
The paper doesn’t mention how an elevated token was acquired. You cannot run bcdedit without privileges. Not all users will have privileges to do this.
by siggen 6y ago
The paper doesn’t mention how an elevated token was acquired. You cannot run bcdedit without privileges. Not all users will have privileges to do this.
- gruez 6y agoYeah this "technique" is a case of being on the other side of this airtight hatchway[1]. If you had the privilege to pull this off, you also can install a kernel rootkit that does the same thing. This technique is probably very easy to detect by antivirus, as it involves several weird operations. [1] https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31283 https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...
- MisterKeylogger 6y agoThe mentioned technique leads to an arbitrary code execution as trusted system user. The Windows Explorer process executes the malicious actions instead of the malware process. By default actions of this trusted system process will NOT be blocked or classified as malware.