AlwaysInstallElevated Abuse
Windows Privilege Escalation
HCKU
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\InstallerHKLM
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\InstallerHCKU y HKLM desde CMD
# Habilitar en HKCU (sin privilegios admin)
reg add "HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /t REG_DWORD /d 1
# Habilitar en HKLM (privilegios de admin)
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /t REG_DWORD /d 1
# Deshabilitar en HKCU
reg delete "HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /f
# Deshabilitar en HKLM (requiere privilegio de admin)
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /fVerificar si AlwaysInstallElevated esta habilitado (Recon)
AlwaysInstallElevated esta habilitado (Recon)Creando MSIs maliciosos básicos para abusar de AlwaysInstallElevated
Last updated