Blog
Shimming Your Way Past UAC
Tue, 05/27/2014
Using Application Compatibility Fixes To Bypass User Account Control
An often-overlooked method that can be used by an attacker to gain elevated code execution is utilization of a framework that is provided by Microsoft to help legacy applications function on newer versions of Windows. That framework is known as the application compatibility toolkit. Unfortunately, in addition to allowing legacy...