I found a new techinque using Virtual Factory for MaintenanceUI COM object(A6BFEA43-501F-456F-A845-983D3AD7B8F0), it works on win81 to win10 21H2 latest my test, and can be GET SYSTEM DIRECTLY.
POC was herehttps://github.com/zcgonvh/TaskSchedulerMisc/blob/master/schuac.cs.
And I believe the shpafact!CElevatedFactoryServer is a new attack surface(~20 Elevated COM Proxy objects on win10 21H2 default).
I found a new techinque using
Virtual Factory for MaintenanceUI
COM object(A6BFEA43-501F-456F-A845-983D3AD7B8F0
), it works on win81 to win10 21H2 latest my test, and can be GET SYSTEM DIRECTLY. POC was herehttps://github.com/zcgonvh/TaskSchedulerMisc/blob/master/schuac.cs. And I believe theshpafact!CElevatedFactoryServer
is a new attack surface(~20 Elevated COM Proxy objects on win10 21H2 default).