.. /ComputerDefaults.exe
Star

UAC bypass

ComputerDefaults.exe is a Windows system utility for managing default applications for tasks like web browsing, emailing, and media playback.

Paths:

Resources:

Acknowledgements:

Detections:

UAC bypass

  1. Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\Software\Classes\ms-settings\Shell\open\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.

    ComputerDefaults.exe
    Use case
    Execute a binary or script as a high-integrity process without a UAC prompt.
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1548.002