logo

Abusing Arbitrary File Deletes to Escalate Privilege and Other Great Tricks (Archive)

ID: 9aad27a7-46a9-5e47-837b-c4069bacdfa5

STIX ID: report--9aad27a7-46a9-5e47-837b-c4069bacdfa5

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
75/100

Date Published: 2024-09-03

Date Updated: 2026-05-01

Author: Simon Zuckerbraun

...
...

This technical blog describes multiple techniques to turn seemingly low-impact filesystem primitives (arbitrary file delete, folder delete/move/rename, deletion of folder contents, and arbitrary folder create) into high-impact outcomes on Windows: SYSTEM privilege escalation by abusing Windows Installer rollback (C:\Config.Msi) to plant malicious rollback files and DLLs, and permanent boot-time denial-of-service by name-squatting driver paths; the post includes proof-of-concept code, detailed stepwise exploit flows, race-condition considerations, and practical notes on reliability and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.