← All OSCP Flashcard Decks

Windows Privilege Escalation Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Windows Privilege Escalation flashcards as text
  1. What is DLL hijacking in the context of Windows privilege escalation?

    Answer: Placing a malicious DLL in a directory searched before the legitimate DLL location

    DLL hijacking exploits Windows's DLL search order by placing a malicious DLL with the correct name in a directory that is searched before the legitimate DLL's directory.

  2. What tool can dump Windows NTLM password hashes from the SAM database when running as SYSTEM?

    Answer: Mimikatz

    Mimikatz's 'lsadump::sam' or 'sekurlsa::logonpasswords' commands can extract NTLM hashes and plaintext credentials from the SAM database and LSASS memory when run with SYSTEM privileges.

  3. What is the purpose of the 'AlwaysInstallElevated' Windows policy and how is it exploited?

    Answer: It allows all users to install updates without admin rights — exploited by creating malicious MSI packages

    When AlwaysInstallElevated is enabled in both HKCU and HKLM, any user can install MSI packages with SYSTEM privileges, allowing privilege escalation via a crafted malicious MSI file.

  4. Which PowerShell command checks whether the current user can modify a specific service's binary?

    Answer: Get-Acl -Path 'C:\path\to\service.exe' | Format-List

    Get-Acl retrieves the security descriptor (ACL) of a file, revealing which users have read, write, or modify permissions on the service binary.

  5. What does the 'accesschk.exe' tool from Sysinternals help identify during Windows privilege escalation?

    Answer: Permissions on files, registry keys, services, and other objects

    Accesschk.exe audits permissions on Windows objects (files, services, registry, kernel objects), making it essential for finding world-writable services, files, or registry keys.

  6. What Windows privilege escalation technique abuses the SeImpersonatePrivilege token right?

    Answer: Juicy Potato / PrintSpoofer token impersonation

    SeImpersonatePrivilege allows impersonating authentication tokens; tools like Juicy Potato, RoguePotato, and PrintSpoofer exploit this to impersonate the SYSTEM token and gain full privileges.