UAC bypass via ICMLuaUtil COM interface

Identifies potential User Account Control (UAC) bypass activity through abuse of the ICMLuaUtil Component Object Model (COM) interface. ICMLuaUtil is an internal Windows COM interface associated with system configuration and elevation-related operations. Because it is registered as an auto-elevated COM object, adversaries can be weaponize it in a manner that results in elevated execution without triggering a standard UAC consent prompt.

Back to all rules