> For the complete documentation index, see [llms.txt](https://ad-lab.gitbook.io/building-a-windows-ad-lab/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ad-lab.gitbook.io/building-a-windows-ad-lab/vulnerabilities-and-misconfigurations-and-attacks/misc/page-3-4.md).

# Bypassing UAC

## Attacking

### How it works

Bypassing UAC is required if you got a shell as an user which has local administrator privileges but isn't running with high privileges. This is a low privileged shell. You want to run in a high privileged shell to migrate processes and dump the LSASS process or SAM. This can be achieved by a UAC bypass and spawning an high integrity shell.

For more information about UAC refer to the documentation from Microsoft: <https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works>

### Tools

* [UACME](https://github.com/hfiref0x/UACME)

### Building UACME

1. Download Visual Studio 2019 on a local W10 machine from [here](https://visualstudio.microsoft.com/vs/older-downloads/).
2. Clone the UACME project.

```
git clone https://github.com/hfiref0x/UACME
```

3\. Open the UACME project by clicking on `uacme.sln`.

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FB5LBAzFNB7jLOBAxIc2G%2Fimage.png?alt=media&amp;token=c1cf7145-3bbd-4731-abae-ca34ebf0c479" alt=""></div>

4\. In the "Solution Explorer" right click on "Akagi" and click on "Properties". Make sure the "Platform Toolset" is set to V142 and click on "Apply" and "OK".

![](https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2Few1NhZa4hAZmeDgj7ICy%2Fimage.png?alt=media\&token=a3d4132b-e570-446c-9e7f-bf7eba89e827)

5\. At the top select the "Release" version and "X64" bit.

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FGj33QZjyTPB5WMTOAeaF%2Fimage.png?alt=media&amp;token=e84a8dbc-1e51-4218-b1d2-bc733864dea8" alt=""></div>

6\. In the "Solution Explorer" right click on "solution aucme" and click on "Build".

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2F2F3z2Ibr99rm2b3UctJd%2Fimage.png?alt=media&amp;token=80e96fd1-b5e7-49a6-ad2e-c08be66f1174" alt=""></div>

7\. The "Output" pane should show that 5 builds are succeeded.

![](https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2Fcw83RC39WXu7I2W9X9Qv%2Fimage.png?alt=media\&token=7eacc3d7-128a-4826-a50e-ad9f5fbe7934)

8\. Go to `C:\Tools\Evasion\UACME\Source\Akagi\output\x64\Release` and copy `Akagi64.exe` to the desktop.

### Executing the attack

1\. The syntax for the executable is `./Akagi64.exe <METHOD> <EXECUTABLE>`. If we run the following command we will abuse the fodhelper method:

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FpHqL1kilACL6ntAuVAOS%2Fimage.png?alt=media&amp;token=40d552ed-3ca7-41cb-9d2b-cf9095315062" alt=""></div>

```
.\Akagi64.exe 34 cmd.exe
```

<div align="left"><img src="https://1033393870-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPqGbN7FCY7Xh4OkOtvin%2Fuploads%2FiCRAjJcO0ARJVclKhAav%2Fimage.png?alt=media&amp;token=8f05e1a4-d974-4d49-b489-e5566fb7d02f" alt=""></div>

2\. And an elevatged prompt started.

## Defending

### Recommendations

* Change the UAC level to always prompt for passwords.
* Keep the Windows version up-to-date, although a lot of UAC bypasses will still work! They get patched from time to time.

### Detection

## References

{% embed url="<https://www.youtube.com/watch?v=RXX0FHM9SEk>" %}

{% embed url="<https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/how-user-account-control-works>" %}
