Windows Privilege Escalation via SeManageVolumePrivilege

· Original article ↗

Summary

A walkthrough shows how a standard Windows user granted SeManageVolumePrivilege can enable it, rewrite Windows directory ACLs, and exploit DLL-loading paths in Print Spooler, WBEM, or Windows Error Reporting to reach SYSTEM.

Key points

  • The demonstrated attack requires a standard user account to have the “Perform volume maintenance tasks” right, which corresponds to SeManageVolumePrivilege.
  • After enabling the privilege in the process token, the attacker uses SeManageVolumeExploit to grant BUILTINUsers write access across the Windows directory tree.
  • The walkthrough demonstrates three DLL-hijacking routes: Print Spooler and Windows Error Reporting for SYSTEM access, and WBEM for an NT AUTHORITY\NETWORK SERVICE shell.
  • The WBEM route can provide a further escalation path because the service account has SeImpersonatePrivilege.
  • The lab uses a Windows 10 target and a standard local account; the article presents the scenarios as demonstrations of a risky user-right misconfiguration.
  • Recommended defenses include restricting the right to necessary service accounts, auditing user-right assignments and ACL changes, controlling DLL loads, and limiting unnecessary Print Spooler and Windows Error Reporting exposure.

Article Details

Topic
Windows privilege escalation through misconfigured SeManageVolumePrivilege and DLL hijacking

Indicators of compromise

TypeIndicatorContext
IPV4192[.]168[.]1[.]8Attacker-controlled Kali Linux host used to stage exploit files and receive reverse-shell callbacks in the demonstration.
URLhxxp[:]//192[.]168[.]1[.]8/EnableAllTokenPrivs[.]ps1Attacker-hosted script fetched to enable the target account's disabled privileges.
URLhxxp[:]//192[.]168[.]1[.]8/phoneinfo[.]dllAttacker-hosted reverse-shell DLL fetched for loading through Windows Error Reporting.
URLhxxp[:]//192[.]168[.]1[.]8/Printconfig[.]dllAttacker-hosted reverse-shell DLL fetched for Print Spooler hijacking.
URLhxxp[:]//192[.]168[.]1[.]8/Report[.]werAttacker-hosted crafted error report fetched for the WerTrigger exploitation path.
URLhxxp[:]//192[.]168[.]1[.]8/SeManageVolumeExploit[.]exeAttacker-hosted exploit executable fetched to rewrite Windows directory permissions.
URLhxxp[:]//192[.]168[.]1[.]8/tzres[.]dllAttacker-hosted reverse-shell DLL fetched for WBEM hijacking.
URLhxxp[:]//192[.]168[.]1[.]8/WerTrigger[.]exeAttacker-hosted exploit component fetched to trigger Windows Error Reporting.

MITRE ATT&CK

Vendors

Products

Tools

Related Articles