typetechniquecreated2026-09-05updated2026-09-05defense-evasionmitre-attckuac-bypassregistryevasion

UAC Bypass via Event Viewer (eventvwr.exe mscfile Hijack)

Abuses the auto-elevation behavior of eventvwr.exe on Windows. Event Viewer is a "Trusted Installer" binary that auto-elevates by invoking the mmc.exe COM object via the mscfile shell handler. By hijacking the registry key Software\Classes\mscfile\shell\open\command, an unprivileged process can redirect execution to an arbitrary payload that runs elevated.

Detection / Fingerprint

Registry SetValue event targeting HKCU\Software\Classes\mscfile\shell\open\command (or HKLM equivalent) with a non-default value. Parent process is not mmc.exe.

Implementation Patterns Observed

In remcos, the binary writes its own path into that registry key, then spawns eventvwr.exe. When Event Viewer auto-elevates, it launches the Remcos payload with high integrity. If the hijack fails, Remcos falls back to disabling UAC entirely via EnableLUA=0.

Reproduce on Your Own VMs

  1. Open regedit as standard user.
  2. Create HKCU\Software\Classes\mscfile\shell\open\command.
  3. Set default value to C:\Windows\System32\cmd.exe /k whoami.
  4. Launch eventvwr.exe from Run dialog.
  5. Observe cmd.exe spawns elevated (High Integrity).
  6. Clean up: delete the registry key.

Defensive Countermeasures

  • Monitor registry changes to mscfile\shell\open\command.
  • Alert on eventvwr.exe spawning child processes other than mmc.exe.
  • Enable UAC in highest-security mode; consider removing eventvwr.exe from auto-elevation allow-list via application control.

Pages Where Observed

  • remcos — primary observed family. ^[entities/remcos.md]
  • 65d3a51a — Remcos v1.7 Pro sample with eventvwr bypass + EnableLUA fallback. ^[/intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html]