logo

Breaking Barriers and Assumptions: Techniques for Privilege Escalation on Windows: Part 1

ID: be5a849f-7d02-58eb-a4d8-b5e72a12ade0

STIX ID: report--be5a849f-7d02-58eb-a4d8-b5e72a12ade0

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
50/100

Date Published: 2024-07-30

Date Updated: 2026-05-01

Author: Michael DePlante and Nicholas Zubrisky

...
...

This report explains link-following (CWE-59) vulnerabilities on Windows where applications transparently follow NTFS junctions, hard links, or symlinks, enabling attackers to redirect privileged file operations. It outlines scouting methods (using Procmon to find writable locations and sensitive file operations), exploitation prerequisites, and observed mitigations (FILE_FLAG_OPEN_REPARSE_POINT, checking reparse tags, protected files, impersonation, and Redirection Guard), focusing on how developers can detect and reduce this class of vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.