3 ms·
Those functions are for use by debuggers, and by default you need administrator rights to call them.
by winternewt 2y ago
Those functions are for use by debuggers, and by default you need administrator rights to call them.
- ale42 2y agoThey are not only for that. The documentation says: Typically but not always, the process with address space that is being written to is being debugged. I don't really see why you'd need admin rights to do so. As far as the process being injected belongs to the same user and is not a protected process (DRM), OpenProcess will happily return a handle with PROCESS_VM_WRITE and PROCESS_VM_OPERATION rights as required by WriteProcessMemory. On the other hand, if you want to inject a system process, you definitely need admin rights.
- winternewt 2y ago> OpenProcess will happily return a handle with PROCESS_VM_WRITE and PROCESS_VM_OPERATION rights Only if the process calling it has SE_DEBUG_NAME privileges, which you must set by opening your own process and then calling AdjustTokenPrivileges. But that will fail unless you have the "Debug Programs" right enabled in the security policy.