HomeSecurityWindows Accessibility bug allows persistence and lateral movement

Windows Accessibility bug allows persistence and lateral movement

A persistent DLL hijacking vulnerability has been identified in Windows Accessibility Narrator, which has been a significant concern for some time. This weakness allows malicious actors to exploit the tool, potentially compromising the security of systems that rely on it for accessibility features.

See also: Windows 11 emergency update fixes serious bug in WinRE

Windows Accessibility
Windows Accessibility bug allows persistence and lateral movement

The vulnerability was first reported in reports dating back to 2013 by security researcher Hexacorn and still exists in modern versions of Windows 10 and 11, allowing attackers with local administrator privileges to achieve silent code execution, persistent system presence, and even remote lateral movement. The discovery by TrustedSec , inspired by VX-Underground repository mining tactics , highlights how everyday accessibility features can be used for malicious purposes.

The technique exploits the loading of MSTTSLocOneCoreEnUS.dll by Narrator.exe from the path %windir%\system32\speech_onecore\engines\tts. By replacing this DLL with a malicious version, attackers can execute arbitrary code when Narrator starts, without requiring exports. The DLL's DllMain attachment function triggers the payload, but the researchers modified it to suspend Narrator's main thread, silencing the tool's audio output and preventing visual cues that could alert users.

A proof-of-concept on GitHub demonstrates this evasion, freezing Narrator while it executes custom code without being detected. Attackers can embed this hijack to automatically run at login by modifying the registry. Under HKCU\Software\Microsoft\Windows NT\CurrentVersion\Accessibility , creating a REG_SZ value named “ configuration ” set to “Narrator” triggers the DLL at user login.

See also: Microsoft: AI becomes a core feature of Windows 11

Windows Accessibility bug allows persistence and lateral movement
Windows Accessibility bug allows persistence and lateral movement

TrustedSec testing confirmed seamless persistence after logoff, with the malicious DLL silently loaded. This method does not require elevated privileges beyond initial access, making it ideal for maintaining a presence in user environments. For broader impact, the technique is extended to SYSTEM-level persistence by applying the same registry change under HKLM, launching Narrator at the login screen with elevated privileges.

The lateral movement adds another layer: attackers with remote registry access via tools like Impacket can deploy the DLL and change HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\SecurityLayer to 0. RDP connection to the target allows Narrator to be activated via Ctrl+Win+Enter upon login, running the payload as SYSTEM before the session is closed, forcing a quick migration of processes for retained access.

The researchers also demonstrated “Bring Your Own Accessibility,” creating custom accessibility tools (ATs) via registry exports and imports, pointing to arbitrary executables, and even UNC network paths for remote payload delivery. Activation via ATBroker.exe /start further enhances flexibility.

See also: Windows 11's dark mode becomes more consistent in File Explorer

Windows Accessibility bug allows persistence and lateral movement
Windows Accessibility bug allows persistence and lateral movement

Although no CVE has yet been assigned, this highlights the risks of unpatched legacy behaviors in accessibility features, urging organizations to closely monitor changes to the registry and DLL paths.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS