Potential privilege elevation via arbitrary section creation
Identifies potential privilege escalation attempts where a non-SYSTEM process creates symbolic links targeting object manager namespaces specific to memory section objects followed by the creation of a SYSTEM process. This behavior may indicate exploitation of arbitrary object directory or section creation vulnerabilities that abuse symbolic link redirection to manipulate privileged operations and gain elevated execution.
- Platform: Windows
- Severity: High
- MITRE Tactic: Privilege Escalation
- MITRE Techniques: T1068