Change.exe

Remote Desktop Services MultiUser Change Utility

Paths

  • c:\windows\system32\change.exe
  • c:\windows\syswow64\change.exe

Commands

Execute

Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.

Use case: Execute an arbitrary executable via trusted system executable.

Privileges: User

change.exe user

Detection