InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
Description
Detects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
Query · sigma
selection: Image|endswith: \msiexec.exe TargetFilename|startswith: C:\Program Files (x86)\Microsoft\Edge\Application TargetFilename|endswith: \elevation_service.exe condition: selection
Known false positives
- Unknown
- Possibly some Microsoft Edge upgrades