Researchers detailed a series of local privilege-escalation attacks against antivirus and EDR products that abused COM hijacking to load attacker-controlled DLLs into trusted front-end processes and then pivot into privileged back-end services. The work showed a recurring design weakness: low-privileged user-facing components were allowed to issue powerful requests to SYSTEM services over named pipes or RPC without sufficient validation. In one generalized attack pattern, modified backend messages were used to write attacker-controlled registry values and alter application paths so that a privileged security process later launched code from a user-writable location, yielding SYSTEM access.
Product-specific cases expanded that pattern across multiple vendors. AVG Internet Security (CVE-2024-6510) was exploited by combining COM hijacking, RPC abuse, self-defense disabling, and a TOCTOU race to swap in a malicious DLL for execution as SYSTEM; Webroot Endpoint Protect (CVE-2023-7241) exposed a file-deletion primitive over \\.\pipe\WRSVCPipe that was chained into DLL hijacking for a SYSTEM shell; Check Point Harmony (CVE-2024-24912) allowed a privileged service to download a DLL to an attacker-chosen path for lock-screen DLL hijacking; and Bitdefender Total Security (CVE-2023-6154) let a privileged backend write arbitrary registry values, enabling service ImagePath hijacking. The findings echo earlier research on brittle hardening controls in products such as VirtualBox, where COM registration abuse and DLL-loading edge cases also undermined process protections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Neodyme detailed a privilege-escalation vulnerability in Bitdefender Total Security, tracked as CVE-2023-6154, in which COM hijacking and reversed IPC allowed a low-privileged attacker to make a privileged service write arbitrary registry values. The proof of concept changed NetSetupSvc's ImagePath and then started the service to execute attacker code as SYSTEM.
Neodyme published details of two local privilege-escalation vulnerabilities discovered via COM hijacking: Webroot Endpoint Protect (CVE-2023-7241) and Check Point Harmony (CVE-2024-24912). In both cases, trusted front-end processes were hijacked and then used to reach privileged backend functionality that enabled SYSTEM-level code execution.
Neodyme described a privilege-escalation vulnerability in AVG Internet Security, tracked as CVE-2024-6510, that combined COM hijacking, RPC abuse, and a TOCTOU race to gain SYSTEM privileges. The attack abused backend functions to disable self-protection and load a malicious DLL through an allow-listed system component.
Neodyme published research describing a general privilege-escalation method that uses COM hijacking to load attacker code into trusted front-end security-product processes and then abuse their communication with SYSTEM back-end services. The post included an example where modified messages caused a privileged back-end to write attacker-controlled registry values, leading to SYSTEM execution after reboot.
Silent Signal published research on breaking antivirus protections, contributing to the broader body of work on weaknesses in security-product self-protection and trust boundaries. The reference provides only the publication date anchor from the URL path.
On 2017-08-01, James Forshaw of Google Project Zero published analysis of three distinct bypass techniques against Oracle VirtualBox's Windows process hardening. The post detailed how the protections could be circumvented to inject arbitrary code into protected VirtualBox processes.
Google Project Zero said Oracle addressed two more VirtualBox process-hardening bypasses, CVE-2017-10204 and CVE-2017-10129, in VirtualBox 5.1.24. The bypasses exploited DLL loading edge cases and SMB image-section caching behavior to enable arbitrary code injection into protected processes.
Google Project Zero reported that Oracle fixed a VirtualBox Windows process-hardening bypass as CVE-2017-3563 in VirtualBox versions 5.0.38 and 5.1.20. The issue involved abusing per-user COM registration and Microsoft-signed components to inject code into protected VirtualBox processes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
neodyme.io
Open sourceneodyme.io
Open sourceneodyme.io
Open sourceneodyme.io
Open sourcegoogleprojectzero.blogspot.com
Open sourceblog.silentsignal.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.