Breaking Barriers and Assumptions: Techniques for Privilege Escalation on Windows: Part 2
ID: 4e0fe2d4-d6c9-5c6e-add2-24a89279fc65
STIX ID: report--4e0fe2d4-d6c9-5c6e-add2-24a89279fc65
Feed Name: Zero Day Initiative (ZDI) Blog
Date Published: 2024-07-31
Date Updated: 2026-05-01
Author: Michael DePlante and Nicholas Zubrisky
This report analyzes a local privilege escalation technique targeting ESET Smart Security's `ekrn.exe`. By writing an EICAR test string to an alternate data stream, polling for `FILE_ATTRIBUTE_NORMAL`, and then creating an Object Manager symbolic link combined with an NTFS junction, an attacker-controlled deletion by `ekrn.exe` can be redirected to `C:\Config.msi`, enabling escalation to `NT AUTHORITY\SYSTEM`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
