Researchers detailed how Microsoft Windows restricts COM and WinRT initialization inside Less Privileged AppContainer (LPAC) sandboxes through the lpacCom capability, and how those checks can be bypassed for in-process components. In LPAC environments without lpacCom, CoInitializeEx and RoInitialize return access denied, which causes later COM and WinRT activation attempts to fail as not initialized. The report ties those restrictions to Windows' COM architecture, where initialization is a prerequisite for object activation and use.
The write-up says in-process activation can still be achieved by manually reproducing normal COM and WinRT loading behavior: reading component registration from the registry, loading the target DLL, and directly calling DllGetClassObject or DllGetActivationFactory. It further claims the lpacCom control is effectively enforced on the client side because combase relies on RtlCheckTokenCapability, making local patching or hooking of that capability check sufficient to bypass the restriction for in-process components. The researchers noted that registryRead access is still required for standard registry-based activation, while out-of-process activation remains blocked and was left for further investigation.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The reference states that Less Privileged AppContainer (LPAC), a more restrictive extension of AppContainer, was introduced in Windows 10.
The reference states that Windows Runtime (WinRT) was introduced with Windows 8 for Windows Store applications, and that AppContainer was introduced in Windows 8 as a sandboxing feature.
A Hunt & Hackett blog post analyzes how COM and WinRT initialization is blocked in LPAC without the lpacCom capability and describes bypass techniques for in-process components, including manual activation and patching or hooking the client-side capability check. The post also notes that registryRead is required for registry-based activation and that out-of-process activation remains blocked.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.