{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/privesc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["execution","persistence","privesc","lolbas"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eMicrosoft Connection Manager Profile Installer (CMSTP.exe) is a legitimate Windows binary designed to install Connection Manager service profiles. Threat actors frequently abuse this utility to execute arbitrary code or bypass UAC. The technique involves manipulating specific registry keys within the App Paths hive, which influences how the operating system handles execution requests or loads associated dynamic link libraries (DLLs). By modifying these registry paths, attackers can force CMSTP to load malicious DLLs or configuration files, facilitating execution in a higher-privileged context. This is a well-documented LOLBAS (Living Off the Land Binary and Script) technique that persists across modern Windows environments, requiring defenders to monitor registry modifications associated with CMSTP's configuration parameters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target system where CMSTP.exe execution is permissible.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious DLL or configuration profile (INF file) to be loaded by CMSTP.\u003c/li\u003e\n\u003cli\u003eAttacker gains sufficient privileges to modify the Windows registry.\u003c/li\u003e\n\u003cli\u003eAttacker performs a write operation to the registry key HKLM or HKCU under Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe.\u003c/li\u003e\n\u003cli\u003eAttacker executes cmstp.exe via command line or automated script.\u003c/li\u003e\n\u003cli\u003eCMSTP.exe references the modified App Paths registry key.\u003c/li\u003e\n\u003cli\u003eCMSTP.exe loads the attacker-supplied DLL or INF file, bypassing security controls or executing arbitrary logic.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, such as privilege escalation, persistence, or payload execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of this technique allows an attacker to execute code with elevated privileges, bypassing standard UAC protections. This facilitates further post-exploitation activities, including credential dumping, lateral movement, or the deployment of ransomware within an organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor registry modifications targeting cmmgr32.exe App Paths.\u003c/li\u003e\n\u003cli\u003eAlert on any write operations to the registry path SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\ that are not associated with authorized system updates.\u003c/li\u003e\n\u003cli\u003eUtilize Sysmon or native Windows Registry auditing to capture the process ID responsible for the registry change, ensuring attribution back to the parent process.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T12:07:17Z","date_published":"2026-09-01T12:07:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cmstp-registry/","summary":"Adversaries leverage the Microsoft Connection Manager Profile Installer (CMSTP) via registry modifications to achieve arbitrary code execution or bypass User Account Control (UAC).","title":"Detection of CMSTP App Paths Registry Modification","url":"https://feed.craftedsignal.io/briefs/2026-09-cmstp-registry/"}],"language":"en","title":"CraftedSignal Threat Feed - Privesc","version":"https://jsonfeed.org/version/1.1"}