logo

Breaking Barriers and Assumptions: Techniques for Privilege Escalation on Windows: Part 2

ID: 4e0fe2d4-d6c9-5c6e-add2-24a89279fc65

STIX ID: report--4e0fe2d4-d6c9-5c6e-add2-24a89279fc65

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-07-31

Date Updated: 2026-05-01

Author: Michael DePlante and Nicholas Zubrisky

...
...

This report analyzes a local privilege escalation technique targeting ESET Smart Security's `ekrn.exe`. By writing an EICAR test string to an alternate data stream, polling for `FILE_ATTRIBUTE_NORMAL`, and then creating an Object Manager symbolic link combined with an NTFS junction, an attacker-controlled deletion by `ekrn.exe` can be redirected to `C:\Config.msi`, enabling escalation to `NT AUTHORITY\SYSTEM`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.