discovered 03 Aug 2026
UACHooker
→ View on GitHubUACHooker is a proof-of-concept reflective DLL designed to exploit the AicLaunchAdminProcess function in explorer.exe for privilege escalation by manipulating UAC prompts. It achieves this by redirecting user-initiated administrative commands to run a specified payload instead, masquerading it as legitimate software, while showing misleading arguments. The tool’s notable features include its ability to create indistinguishable UAC prompts for unsigned executables and the potential for future enhancements such as support for additional hooking libraries and broader target applications.