这个问题是关于为什么在Windows 8上忽略了SeCreateSymbolicLinkPrivilege的后续问题。
给定条件:
附录:
非提升的管理员用户:
给定条件:
- 用户在管理员组中
- 关闭UAC不是我的选择。
- 无法运行提升。
附录:
非提升的管理员用户:
C:\dayforce\SharpTop>whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ==================================== ========
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
C:\dayforce\SharpTop>
一般用户:
C:\Windows\system32>whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ==================================== ========
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
SeCreateSymbolicLinkPrivilege Create symbolic links Disabled
C:\Windows\system32>
注意,普通用户拥有SeCreateSymbolicLinkPrivilege
权限,因为我已在安全策略中启用了它。但管理员用户则没有此权限,因为这对其标准用户令牌没有影响!
CreateRestrictedToken
来创建自定义沙盒。 - Eryk Sun