Abusing Arbitrary File Deletes to Escalate Privilege and Other Great Tricks (Archive)
ID: 9aad27a7-46a9-5e47-837b-c4069bacdfa5
STIX ID: report--9aad27a7-46a9-5e47-837b-c4069bacdfa5
Feed Name: Zero Day Initiative (ZDI) Blog
This technical blog describes multiple techniques to turn seemingly low-impact filesystem primitives (arbitrary file delete, folder delete/move/rename, deletion of folder contents, and arbitrary folder create) into high-impact outcomes on Windows: SYSTEM privilege escalation by abusing Windows Installer rollback (C:\Config.Msi) to plant malicious rollback files and DLLs, and permanent boot-time denial-of-service by name-squatting driver paths; the post includes proof-of-concept code, detailed stepwise exploit flows, race-condition considerations, and practical notes on reliability and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
