Bypass User Account Control

T1548.002

Sub-technique of T1548 Abuse Elevation Control Mechanism.View on attack.mitre.org

About this technique

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

If the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated Component Object Model objects without prompting the user through the UAC notification box. An example of this is use of Rundll32 to load a specifically crafted DLL which loads an auto-elevated Component Object Model object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user.

Many methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as:

* eventvwr.exe can auto-elevate and execute a specified binary or script.

Another bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.

Detection rules74

Rules on DetectionCode tagged with T1548.002.

Sigma56

RuleLevelLog source
HackTool - Empire PowerShell UAC Bypasscriticalwindows / process_creation
TrustedPath UAC Bypass Patterncriticalwindows / process_creation
Bypass UAC Using DelegateExecutehighwindows / registry_set
Bypass UAC Using SilentCleanup Taskhighwindows / registry_set
Bypass UAC via CMSTPhighwindows / process_creation
Bypass UAC via Fodhelper.exehighwindows / process_creation
Bypass UAC via WSReset.exehighwindows / process_creation
CMSTP UAC Bypass via COM Object Accesshighwindows / process_creation
Explorer NOUACCHECK Flaghighwindows / process_creation
HackTool - UACMe Akagi Executionhighwindows / process_creation
HackTool - WinPwn Executionhighwindows / process_creation
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_script
Potentially Suspicious Event Viewer Child Processhighwindows / process_creation
PowerShell Web Access Feature Enabled Via DISMhighwindows / process_creation
Shell Open Registry Keys Manipulationhighwindows / registry_event

Splunk18

RuleTypeRiskData source
Disable UAC Remote RestrictionTTPNULLSysmon EventID 13
Disabling Remote User Account ControlTTPNULLSysmon EventID 13
Eventvwr UAC BypassTTPNULLSysmon EventID 13
FodHelper UAC BypassTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
NET Profiler UAC bypassTTPNULLSysmon EventID 13
Sdclt UAC BypassTTPNULLSysmon EventID 12, Sysmon EventID 13
SilentCleanup UAC BypassTTPNULLSysmon EventID 13
SLUI RunAs ElevatedTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
SLUI Spawning a ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
UAC Bypass MMC Load Unsigned DllTTPNULLSysmon EventID 7
Windows Bypass UAC via Pkgmgr ToolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows ComputerDefaults Spawning a ProcessTTPNULLSysmon EventID 1
Windows DISM Install PowerShell Web AccessTTPNULLWindows Event Log Security 4688, Sysmon EventID 1
Windows Mock Trusted Directory MSC File CreationTTPNULLSysmon EventID 11
Windows Suspicious Child Process of Consent.EXEAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups11

Software51

Show 27 more

Campaigns1

Procedure examples63

Groups11

Used byProcedure example
GroupAPT29

APT29 has bypassed UAC.

GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

GroupCobalt Group

Cobalt Group has bypassed UAC.

GroupEarth Lusca

Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.

GroupEvilnum

Evilnum has used PowerShell to bypass UAC.

GroupMedusa Group

Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.

View all 11 groups examples

Software51

Used byProcedure example
MalwareAppleJeus

AppleJeus has presented the user with a UAC prompt to elevate privileges while installing.

MalwareAutoIt backdoor

AutoIt backdoor attempts to escalate privileges by bypassing User Access Control.

MalwareAvaddon

Avaddon bypasses UAC using the CMSTPLUA COM interface.

MalwareBad Rabbit

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.

MalwareBADHATCH

BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC.

MalwareBitPaymer

BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.

MalwareBlackCat

BlackCat can bypass UAC to escalate privileges.

MalwareBlackEnergy

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.

View all 51 software examples

Campaigns1

Used byProcedure example
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections.

References8

  1. Davidson Windows Open source
    Davidson, L. (n.d.). Windows 7 UAC whitelist. Retrieved November 12, 2014.
  2. Fortinet Fareit Open source
    Salvio, J., Joven, R. (2016, December 16). Malicious Macro Bypasses UAC to Elevate Privilege for Fareit Malware. Retrieved December 27, 2016.
  3. Github UACMe Open source
    UACME Project. (2016, June 16). UACMe. Retrieved July 26, 2016.
  4. MSDN COM Elevation Open source
    Microsoft. (n.d.). The COM Elevation Moniker. Retrieved July 26, 2016.
  5. SANS UAC Bypass Open source
    Medin, T. (2013, August 8). PsExec UAC Bypass. Retrieved June 3, 2016.
  6. TechNet How UAC Works Open source
    Lich, B. (2016, May 31). How User Account Control Works. Retrieved June 3, 2016.
  7. TechNet Inside UAC Open source
    Russinovich, M. (2009, July). User Account Control: Inside Windows 7 User Account Control. Retrieved July 26, 2016.
  8. enigma0x3 Fileless UAC Bypass Open source
    Nelson, M. (2016, August 15). "Fileless" UAC Bypass using eventvwr.exe and Registry Hijacking. Retrieved December 27, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.