UAC Bypass via Event Viewer (eventvwr.exe mscfile Hijack)
Abuses the auto-elevation behavior of eventvwr.exe on Windows. Event Viewer is a "Trusted Installer" binary that auto-elevates by invoking the mmc.exe COM object via the mscfile shell handler. By hijacking the registry key Software\Classes\mscfile\shell\open\command, an unprivileged process can redirect execution to an arbitrary payload that runs elevated.
Detection / Fingerprint
Registry SetValue event targeting HKCU\Software\Classes\mscfile\shell\open\command (or HKLM equivalent) with a non-default value. Parent process is not mmc.exe.
Implementation Patterns Observed
In remcos, the binary writes its own path into that registry key, then spawns eventvwr.exe. When Event Viewer auto-elevates, it launches the Remcos payload with high integrity. If the hijack fails, Remcos falls back to disabling UAC entirely via EnableLUA=0.
Reproduce on Your Own VMs
- Open
regeditas standard user. - Create
HKCU\Software\Classes\mscfile\shell\open\command. - Set default value to
C:\Windows\System32\cmd.exe /k whoami. - Launch
eventvwr.exefrom Run dialog. - Observe
cmd.exespawns elevated (High Integrity). - Clean up: delete the registry key.
Defensive Countermeasures
- Monitor registry changes to
mscfile\shell\open\command. - Alert on
eventvwr.exespawning child processes other thanmmc.exe. - Enable UAC in highest-security mode; consider removing
eventvwr.exefrom auto-elevation allow-list via application control.
Pages Where Observed
- remcos — primary observed family. ^[entities/remcos.md]
65d3a51a— Remcos v1.7 Pro sample with eventvwr bypass + EnableLUA fallback. ^[/intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html]