Skip to content
Threat Feed

Tag

Uac-Bypass

9 briefs RSS
high advisory

UAC Bypass Attempt via Windows Directory Masquerading

Detects attempts to bypass User Account Control (UAC) by masquerading as a trusted Microsoft Windows directory, abusing a trailing-space in the path to execute code with elevated privileges.

Elastic Endpoint +4 privilege-escalation uac-bypass windows
2r 1t
high advisory

UAC Bypass via Event Viewer

Detects User Account Control (UAC) bypass attempts using eventvwr.exe to execute code with elevated permissions by identifying child processes of eventvwr.exe, excluding mmc.exe and WerFault.exe, which may indicate unauthorized privilege escalation.

Microsoft Defender XDR +3 privilege-escalation uac-bypass windows
2r 1t
high advisory

UAC Bypass via ICMLuaUtil Elevated COM Interface

Detects User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface, where attackers may attempt to stealthily execute code with elevated permissions, potentially leading to privilege escalation.

Elastic Defend +2 privilege-escalation uac-bypass windows
2r 1t
medium advisory

UAC Bypass via Windows Firewall MMC Snap-In Hijack

Attackers bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in to execute code with elevated permissions, potentially leading to system compromise.

Windows uac-bypass privilege-escalation windows-firewall mmc
2r 2t
high advisory

FodHelper UAC Bypass Attempt

Detection of fodhelper.exe execution, which is known to exploit User Account Control (UAC) bypass by leveraging specific registry keys, potentially leading to privilege escalation.

Windows uac-bypass privilege-escalation fodhelper
2r 2t
medium advisory

UAC Bypass via DiskCleanup Scheduled Task Hijack

Attackers bypass User Account Control (UAC) to stealthily execute code with elevated permissions by hijacking the DiskCleanup Scheduled Task, leveraging specific arguments with non-standard executables.

Windows uac-bypass privilege-escalation
2r 3t
high advisory

Windows ComputerDefaults Process Spawning Detection

The ComputerDefaults.exe process, used for managing default application associations in Windows, can be exploited by attackers to bypass User Account Control (UAC) and execute unauthorized code with elevated privileges, which is detected by monitoring abnormal parent-child process relationships.

Windows privilege-escalation uac-bypass
2r 1t
medium advisory

UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer

This threat brief details a UAC bypass technique leveraging the Internet Explorer Add-On Installer (ieinstal.exe) and Component Object Model (COM) to execute arbitrary code with elevated privileges.

Microsoft Defender XDR +2 uac-bypass privilege-escalation com ieinstal
2r 3t
high advisory

UAC Bypass via ICMLuaUtil Elevated COM Interface

Attackers attempt to bypass User Account Control (UAC) to stealthily execute code with elevated permissions by abusing the ICMLuaUtil Elevated COM interface, spawning processes from dllhost.exe with specific arguments.

Windows privilege-escalation uac-bypass
2r 3t