UAC bypass via Control Panel applet execution hijack

Identifies attempts to bypass User Account Control (UAC) by abusing trusted Control Panel execution paths to achieve unauthorized privilege escalation. Attackers leverage the implicit trust and auto-elevation behavior of Control Panel components to execute arbitrary code with elevated privileges. By manipulating how Control Panel applets or associated shell handlers are resolved, adversaries can cause privileged system processes to launch attacker-controlled payloads without triggering a UAC prompt.

Back to all rules