.. / Wsreset.exe
Star

Used to reset Windows Store settings according to its manifest file


Paths:


Resources:
https://www.activecyber.us/activelabs/windows-uac-bypass
https://twitter.com/ihack4falafel/status/1106644790114947073
https://github.com/hfiref0x/UACME/blob/master/README.md

Acknowledgement:
Hashim Jawad - @ihack4falafel


Detection:
wsreset.exe launching child process other than mmc.exe
Creation or modification of the registry value HKCU\Software\Classes\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\Shell\open\command



UAC bypass

During startup, wsreset.exe checks the registry value HKCU\Software\Classes\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\Shell\open\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.
wsreset.exe
Usecase:Execute a binary or script as a high-integrity process without a UAC prompt.
Privileges required:User
OS:Windows 10
Mitre:T1088