July 2019
Intermediate to advanced
712 pages
17h 36m
English
Before we can use getsystem to perform a privilege escalation attack, we first need to bypass UAC. To list all the available exploits that will allow us to bypass UAC, we can use the search command as follows:

Without going into detail about each exploitation technique, we will try to use the Windows Escalate UAC Protection Bypass to bypass Windows UAC by utilizing the trusted publisher certificate through process injection. This module bypasses Windows UAC by utilizing the trusted publisher certificate through process injection, spawning a second shell with the UAC flag turned off:
meterpreter > background [*] Backgrounding ...
Read now
Unlock full access