UAC bypass via elevated Internet Explorer add-on installer COM interface

Identifies potential User Account Control (UAC) bypass activity involving the elevated Internet Explorer add-on installation mechanism exposed through a COM interface. Adversaries can take advantage of scenarios in which legacy Internet Explorer components are abused to execute code with high integrity outside of standard user consent flows.

Back to all rules