Run the program with the specified permission level (C++20 required)
Run the program with the specified permission level (C++20 required)
Run the program with the specified permission level
Install Privexec by baulk
baulk install wsudo
wsudo --version
Or you can download it directly, use Exeplorer or 7z and other tools to extract and then use Privexec, download link: https://github.com/M2Team/Privexec/releases/latest
Privexec and wsudo can resolve aliases. In addition, wsudo adds or deletes aliases. It is also a good choice to use vscode to edit Privexec.json to modify aliases. When Privexec is installed via baulk, the storage directory of Privexec.json is $BAULK_ROOT/bin/etc. If Privexec Download and unzip directly, then Privexec.json will be in the same directory as Privexec.exe.
{
"alias": [
{
"description": "Edit Hosts",
"name": "edit-hosts",
"target": "Notepad %windir%\\System32\\Drivers\\etc\\hosts"
},
{
"description": "Windows Debugger",
"name": "windbg",
"target": "\"%ProgramFiles(x86)%\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe\""
}
]
}
Alias:
AppContainer:
wsudo usage:
wsudo Verbose Mode:
AppContainer Exec
Privexec is a GUI client. When running as a standard user, you can start the administrator process; when running as an administrator, you can elevate the privileges to System or TrustedInstaller. It should be noted that System or TrustedInstaller has too many privileges, which can easily damage the system operation. Be careful when using it.
AppExec is a program that starts the AppContainer process. Some developers use this program to study the running details of Windows AppContainer and the vulnerabilities of AppContaner. UWP applications run in the AppContainer container.
wsudo is the console version of Privexec/AppExec. The detailed help is as follows:
wsudo usage:
…
When Privexec, AppExec, wsudo launch commands, the command line and launch directory support deduction via ExpandEnvironmentString.
The wsudo visible and wait related parameters are --hide --wait --new-console. The corresponding situation is as follows:
| PE Subsystem | No relevant parameters |
--new-console |
--hide |
|---|---|---|---|
| Windows CUI | wait/Inheritance console | no wait/New console | no wait/No console |
| Windows GUI | no wait/New UI | no wait/New UI | no wait/No window |
Windows CUI -wait |
wait/Inheritance console | wait/New console | wait/No console |
Windows GUI -wait |
wait/New UI | wait/New UI | wait/No window |
When wsudo starts the administrator process as a standard user, if it is currently running in the console, it supports inheriting the console window. If it is not running in the console, it can do nothing. The newer Cygwin currently supports the newer Windows 10 ConPty starts the console, so it can inherit the console window, which is the terminal. The picture below is the proof.
wsudo exec administrator process under mintty (Turn on ConPty):
wsudo support -e/--env to set environment. such as:
::curl must enabled multiple SSL backends.
wsudo -U -V --env CURL_SSL_BACKEND=schannel curl --verbose -I https://nghttp2.org
The environment variables will be deduced according to the Batch mechanism, that is, the environment variables are marked with matching %.
# powershell
.\bin\wsudo.exe -n -e 'PATH=%PATH%;%TEMP%' -U cmd
::cmd
wsudo -e "PATH=%PATH%;%TEMP%" -n -U cmd
see: changelog.md
This project use MIT License, and JSON use https://github.com/nlohmann/json , some API use NSudo, but rewrite it.
No open issues yet, or sync has not completed.