Windows 7 Escalation of Privilege

Dear all,
This article is related to windows 7 Escalation of Privilege which was identified by Zero Day Initiative (Article link)
Here is the short version of how to escalate the Privilege if your windows 7 is not updated in/after Nov 2019.

  1. 1st you have to download an application which is signed by old Microsoft  certificate.
  2. Right click on it and go to properties and click on UNLOCK button.
  3. Right click on the application and run as administrator.
  4. UAC box will appear.
  5. Click on Show details, it will show you a Hyper Link, click on it.
  6. Certificate popup box will appear, there will be hyper link in front of ISSUED By row.
  7. Click it and it will open IE running as system privileges, close the all popup boxes. and open the minimized IE.
  8. Click on setting buttons and click on Save AS from there you can go to windows/system32 directory and run a CMD.
Exploitation Video is below:

https://www.youtube.com/watch?v=3BQKpPNlTSo


Also below are the links of Old signed "Microsoft HTML help control" application.

Link1:
http://originaldll.com/download/27174.exe
Link2:
https://www.mediafire.com/file/lamli5y4sr8cenr/Microsoft_HTML_HELP_Control.exe/file 
https://www.mediafire.com/file/lamli5y4sr8cenr/Microsoft_HTML_HELP_Control.exe/file

Link3:
http://www.unitconverterpro.com/hhupd.exe


 Thanks

https://www.mediafire.com/file/lamli5y4sr8cenr/Microsoft_HTML_HELP_Control.exe/file

Comments

Popular posts from this blog

GRANDING UTime Master - IDOR (CVE-2023-45393)

GRANDING UTime Master - Stored XSS (CVE-2023-45391)

Ericsson BSCS iX R18 Billing & Rating (ADMX, MX) - Stored XSS (CVE-2020-29144, CVE-2020-29145)