Videos / Defcon / Wietze Beukema: Environment Variables as a Way to Hijack Legitimate Applications

Wietze Beukema: Environment Variables as a Way to Hijack Legitimate Applications

Duration: 41min 51sec Type: Presentation (lecture) Playlist: 70 of 146 in Defcon
A DEF CON 30 talk on a stealthier alternative to classic DLL hijacking — abusing process-level environment variables to take control of legitimate applications.

The speaker demonstrates that more than 80 built-in Windows executables are vulnerable to this technique, creating new opportunities for UAC bypass and privilege escalation while maintaining a minimal forensic footprint.