AlwaysInstallElevated
Last updated
Last updated
AlwaysInstallElevated is a misconfiguration that installs all msi packages as system. Wheels spinning?
Query the registry for the misconfiguration
Create a malicious msi file
Pop a shell
You can get a quick win by using the Write-UserAddMSI function from PowerUp.
This function will add a backdoor user to the Local Administrators Group
An RDP sessions is required for this