Yet another sdclt UAC bypass
#1
Quote:1. Origin of the bypass
As often with UAC, the flaw comes from an auto-elevated process. These processes have the particularity to run with high integrity level without prompting the local admin with the usual UAC window. If the user running with medium privileges can make these process load a dll or execute a command, UAC bypass is performed.
In our case, the executable is sdclt.exe. Sdclt is used in the context of Windows backup and restore mechanisms. You can check it auto-elevates using Sysinternals Sigcheck:
Code:
sigcheck.exe -m C:\Windows\System32\sdclt.exe | findstr autoElevate
       <autoElevate  xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</autoElevate>

Note: There are already a couple of known ways to abuse sdclt.exe into bypassing UAC. You can read about those two methods on Matt Nelson’s blog: The method I found is fileless and is based on COM hijacking.
Some interesting events which occur when sdclt.exe is called from a medium integrity process:
  • It runs another process of sdclt.exe with high privilege

  • The high privilege sdclt process calls C:\Windows\System32\control.exe

  • Control.exe process runs with high privilege and ....
[Image: sdclt_name_not_found.png]
Using Sysinternals Procmon, we can see that control.exe is failing to find an open command for the "folder" object in the current user registry (HKCU).
This is very good sign for someone looking to bypass UAC! That is because UAC privileges are not required to write in there so we can basically make an elevated process run a command even if we are in the context of medium integrity process.
2. Exploit the bypass
You can easily test this UAC bypass with a few command lines.
Setup the registry:

Code:
reg add "HKCU\Software\Classes\Folder\shell\open\command" /d "cmd.exe /c notepad.exe" /f && reg add HKCU\Software\Classes\Folder\shell\open\command /v "DelegateExecute" /f

Trigger the bypass:
Code:
%windir%\system32\sdclt.exe

You can watch notepad.exe pop with high integrity level.
[Image: procexp2.png]
After that, do not forget to clean the registry with:
Code:
reg delete "HKCU\Software\Classes\Folder\shell\open\command" /f


Read here: http://blog.sevagas.com/?Yet-another-sdclt-UAC-bypass

License : Copyright Emeric Nasi, some rights reserved

This work is licensed under a Creative Commons Attribution 4.0 International License.
[-] The following 1 user says Thank You to browneylad for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WinRAR 7.20
WinRAR 7.20 (stabl...harlan4096 — 10:27
Vivaldi 7.8 Build 3925.62
Vivaldi 7.8 Build ...harlan4096 — 09:56
New Windows 11 Preview Adds Sysmon, Fixe...
Microsoft has rele...harlan4096 — 09:30
Android 16 February 2026 Security Update...
Google has begun t...harlan4096 — 08:59
Mozilla Firefox Browser 147.0.3
Mozilla Firefox Br...harlan4096 — 07:44

[-]
Birthdays
Today's Birthdays
avatar (48)Michaelecozy
Upcoming Birthdays
avatar (47)hapedDow
avatar (46)komriwat
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)delsreehRob
avatar (44)pyotrded
avatar (41)oecmecodo
avatar (40)ShakitaSmobe
avatar (49)tsorenHievy
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (41)svoyaEnuct
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (41)yposegij
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>