Potential privilege elevation via arbitrary section creation
Identifies potential privilege escalation attempts where a non-SYSTEM process creates symbolic links targeting object manager namespaces specific to memory section objects followed by the creation of a SYSTEM process. This behavior may indicate exploitation of arbitrary object directory or section creation vulnerabilities that abuse symbolic link redirection to manipulate privileged operations and gain elevated execution.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Escalada de privilegios
- Técnicas MITRE: T1068