Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
UACME — 击败Windows用户账户控制 | Kitploit
工具/GitHubGitHub/hfiref0x/uacme
权限提升漏洞利用学习与教育红队
GitHubhfiref0x/uacme

UACME

击败Windows用户账户控制

查看仓库
7.7k1.4k442个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Build status Visitors

UACMe

通过滥用内置的 Windows AutoElevate 后门来绕过 Windows 用户账户控制。该项目演示了多种 UAC 绕过技术,并作为理解 Windows 安全机制的教育资源。

⚠️ 警告: 该工具演示了可能被恶意利用的安全漏洞。请负责任地使用,并仅限在受控环境中使用。

系统要求

  • 操作系统: Windows 7/8/8.1/10/11 (x86-32/x64, 客户端版本;部分方法同样适用于服务器版本)
  • 用户账户: 具有管理员权限的账户,且 UAC 设置为默认级别

使用方法

通过命令行使用以下语法运行可执行文件:``` akagi32.exe [Method_Number] [Optional_Command]

或者```
akagi64.exe [Method_Number] [Optional_Command]

Parameters:

  • Method_Number: 对应 UAC 绕过方法的编号(请参阅下方的方法列表)
  • Optional_Command: 要使用提升权限运行的 executable 文件的完整路径
    • 如果省略,程序将启动一个提升的命令提示符(%systemroot%\system32\cmd.exe)

Examples:```

akagi32.exe 23 akagi64.exe 61 akagi32.exe 23 c:\windows\system32\calc.exe akagi64.exe 61 c:\windows\system32\charmap.exe

> **注意**:自 3.5.0 版本起,所有此前被“修复”的方法均已视为过时并被移除。如需使用,请参考 [v3.2.x 分支](https://github.com/hfiref0x/UACME/tree/v3.2.x)。

> **注意**:自 3.7.0 版本起,3.5.0 至 3.7.0 之间被“修复”的方法已从 UACMe 方法表中移除。如需使用,请参考 [v3.6.x_plus 分支](https://github.com/hfiref0x/UACME/tree/v3.6.x_plus)。这些方法的代码仍保留在当前分支中,仅供历史参考。

<details>
  <summary>键(点击展开/折叠)</summary>1. 作者: Leo Davidson
   * 类型: DLL劫持
   * 方法: IFileOperation
   * 目标: \system32\sysprep\sysprep.exe
   * 组件: cryptbase.dll
   * 实现: ucmStandardAutoElevation   
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 8.1 (9600)
      * 修复方式: sysprep.exe 加固 LoadFrom 清单元素
   * 代码状态: 自 v3.5.0 移除 :tractor:
2. 作者: Leo Davidson 衍生
   * 类型: DLL劫持
   * 方法: IFileOperation
   * 目标: \system32\sysprep\sysprep.exe
   * 组件: ShCore.dll
   * 实现: ucmStandardAutoElevation
   * 适用版本: Windows 8.1 (9600)
   * 修复版本: Windows 10 TP (> 9600)
      * 修复方式: ShCore.dll 移至 \KnownDlls 的副作用
   * 代码状态: 自 v3.5.0 移除 :tractor:
3. 作者: Leo Davidson 衍生,由 WinNT/Pitou 修改
   * 类型: DLL劫持
   * 方法: IFileOperation
   * 目标: \system32\oobe\setupsqm.exe
   * 组件: WdsCore.dll
   * 实现: ucmStandardAutoElevation
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TH2 (10558)
      * 修复方式: OOBE 重新设计的副作用
   * 代码状态: 自 v3.5.0 移除 :tractor:
4. 作者: Jon Ericson, WinNT/Gootkit, mzH
   * 类型: AppCompat
   * 方法: RedirectEXE Shim
   * 目标: \system32\cliconfg.exe
   * 组件: -
   * 实现: ucmShimRedirectEXE
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TP (> 9600)
      * 修复方式: Sdbinst.exe 自动提权移除,其余 Windows 版本通过 KB3045645/KB3048097
   * 代码状态: 自 v3.5.0 移除 :tractor:
5. 作者: WinNT/Simda
   * 类型: 提升COM接口
   * 方法: ISecurityEditor
   * 目标: HKLM 注册表项
   * 组件: -
   * 实现: ucmSimdaTurnOffUac
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TH1 (10147)
      * 修复方式: ISecurityEditor 接口方法变更
   * 代码状态: 自 v3.5.0 移除 :tractor:
6. 作者: Win32/Carberp
   * 类型: DLL劫持
   * 方法: WUSA
   * 目标: \ehome\mcx2prov.exe, \system32\migwiz\migwiz.exe
   * 组件: WdsCore.dll, CryptBase.dll, CryptSP.dll
   * 实现: ucmWusaMethod
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TH1 (10147)
      * 修复方式: 移除了 WUSA /extract 选项
   * 代码状态: 自 v3.5.0 移除 :tractor:
7. 作者: Win32/Carberp 衍生
   * 类型: DLL劫持
   * 方法: WUSA
   * 目标: \system32\cliconfg.exe
   * 组件: ntwdblib.dll
   * 实现: ucmWusaMethod
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TH1 (10147)
      * 修复方式: 移除了 WUSA /extract 选项
   * 代码状态: 自 v3.5.0 移除 :tractor:
8. 作者: Leo Davidson 衍生,由 Win32/Tilon 修改
   * 类型: DLL劫持
   * 方法: IFileOperation
   * 目标: \system32\sysprep\sysprep.exe
   * 组件: Actionqueue.dll
   * 实现: ucmStandardAutoElevation
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 8.1 (9600)
      * 修复方式: sysprep.exe 加固 LoadFrom 清单
   * 代码状态: 自 v3.5.0 移除 :tractor:
9. 作者: Leo Davidson, WinNT/Simda, Win32/Carberp 衍生
   * 类型: DLL劫持
   * 方法: IFileOperation, ISecurityEditor, WUSA
   * 目标: IFEO 注册表项, \system32\cliconfg.exe
   * 组件: 攻击者定义的应用程序验证器 DLL
   * 实现: ucmAvrfMethod
   * 适用版本: Windows 7 (7600)
   * 修复版本: Windows 10 TH1 (10147)
      * 修复方式: 移除了 WUSA /extract 选项,ISecurityEditor 接口方法变更
   * 代码状态: 自 v3.5.0 移除 :tractor:
10. 作者: WinNT/Pitou, Win32/Carberp 衍生
      * 类型: DLL劫持
      * 方法: IFileOperation, WUSA
      * 目标: \system32\\{新}或{现有}\\{自动提权}.exe,例如 winsat.exe
      * 组件: 攻击者定义的 dll,例如 PowProf.dll, DevObj.dll
      * 实现: ucmWinSATMethod
      * 适用版本: Windows 7 (7600)
      * 修复版本: Windows 10 TH2 (10548) 
        * 修复方式: AppInfo 提升应用程序路径控制强化
      * 代码状态: 自 v3.5.0 移除 :tractor:
11. 作者: Jon Ericson, WinNT/Gootkit, mzH
      * 类型: AppCompat
      * 方法: Shim 内存补丁
      * 目标: \system32\iscsicli.exe
      * 组件: 攻击者准备的 shellcode
      * 实现: ucmShimPatch
      * 适用版本: Windows 7 (7600)
      * 修复版本: Windows 8.1 (9600)
         * 修复方式: Sdbinst.exe 自动提权移除,其余 Windows 版本通过 KB3045645/KB3048097
      * 代码状态: 自 v3.5.0 移除 :tractor:
12. 作者: Leo Davidson 衍生
      * 类型: DLL劫持
      * 方法: IFileOperation
      * 目标: \system32\sysprep\sysprep.exe
      * 组件: dbgcore.dll
      * 实现: ucmStandardAutoElevation
      * 适用版本: Windows 10 TH1 (10240)
      * 修复版本: Windows 10 TH2 (10565)
        * 修复方式: sysprep.exe 清单已更新
      * 代码状态: 自 v3.5.0 移除 :tractor:
13. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system32\mmc.exe EventVwr.msc
     * 组件: elsext.dll
     * 实现: ucmMMCMethod
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS1 (14316)
        * 修复方式: 移除了缺失的依赖项
      * 代码状态: 自 v3.5.0 移除 :tractor:
14. 作者: Leo Davidson, WinNT/Sirefef 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system\credwiz.exe, \system32\wbem\oobe.exe
     * 组件: netutils.dll
     * 实现: ucmSirefefMethod
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 TH2 (10548)
        * 修复方式: AppInfo 提升应用程序路径控制强化
      * 代码状态: 自 v3.5.0 移除 :tractor:
15. 作者: Leo Davidson, Win32/Addrop, Metasploit 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system32\cliconfg.exe
     * 组件: ntwdblib.dll
     * 实现: ucmGenericAutoelevation
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS1 (14316)
        * 修复方式: Cliconfg.exe 自动提权移除
      * 代码状态: 自 v3.5.0 移除 :tractor:
16. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system32\GWX\GWXUXWorker.exe, \system32\inetsrv\inetmgr.exe
     * 组件: SLC.dll
     * 实现: ucmGWX
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS1 (14316)
        * 修复方式: AppInfo 提升应用程序路径控制及 inetmgr 可执行文件加固
      * 代码状态: 自 v3.5.0 移除 :tractor:
17. 作者: Leo Davidson 衍生
     * 类型: DLL劫持(导入转发)
     * 方法: IFileOperation
     * 目标: \system32\sysprep\sysprep.exe
     * 组件: unbcl.dll
     * 实现: ucmStandardAutoElevation2
     * 适用版本: Windows 8.1 (9600)
     * 修复版本: Windows 10 RS1 (14371)
        * 修复方式: sysprep.exe 清单已更新
      * 代码状态: 自 v3.5.0 移除 :tractor:
18. 作者: Leo Davidson 衍生
     * 类型: DLL劫持(清单)
     * 方法: IFileOperation
     * 目标: \system32\taskhost.exe, \system32\tzsync.exe(任何不含清单的 ms 可执行文件)
     * 组件: 攻击者定义
     * 实现: ucmAutoElevateManifest
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS1 (14371)
        * 修复方式: 清单解析逻辑已审查
      * 代码状态: 自 v3.5.0 移除 :tractor:
19. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system32\inetsrv\inetmgr.exe
     * 组件: MsCoree.dll
     * 实现: ucmInetMgrMethod
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS1 (14376)
        * 修复方式: inetmgr.exe 可执行文件清单加固,MitigationPolicy->ProcessImageLoadPolicy->PreferSystem32Images
      * 代码状态: 自 v3.5.0 移除 :tractor:
20. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation
     * 目标: \system32\mmc.exe, Rsop.msc
     * 组件: WbemComn.dll
     * 实现: ucmMMCMethod
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS3 (16232)
        * 修复方式: 目标要求 wbemcomn.dll 必须由 MS 签名
      * 代码状态: 自 v3.5.0 移除 :tractor:
21. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
     * 方法: IFileOperation, SxS DotLocal
     * 目标: \system32\sysprep\sysprep.exe
     * 组件: comctl32.dll
     * 实现: ucmSXSMethod
     * 适用版本: Windows 7 (7600)
     * 修复版本: Windows 10 RS3 (16232)
        * 修复方式: MitigationPolicy->ProcessImageLoadPolicy->PreferSystem32Images
      * 代码状态: 自 v3.5.0 移除 :tractor:
22. 作者: Leo Davidson 衍生
     * 类型: DLL劫持
下载工具