MSIX Runtime HKCU CreateKey

%3CLINGO-SUB%20id%3D%22lingo-sub-3301668%22%20slang%3D%22en-US%22%3EMSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3301668%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20have%20a%20package%20that%20contains%20the%20registry%20key%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20HKEY_CURRENT_USER%5CSoftware%5CVendor%3C%2FP%3E%0A%3CP%3EAnd%20you%20run%20that%20package%20and%20it%20creates%20a%20subkey%20under%20Vendor%20named%20%22Settings%22.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20the%20application%20calls%20CreateKey%20against%20the%20%22Vendor%22%20key%20requesting%20access%20%22MaximumAllowed%22%2C%20it%20is%20granted%20permissions%20%22Read%2FWrite.%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20the%20application%20calls%20CreateKey%20against%20%22Settings%22%20key%20requesting%20access%20%22MaximumAllowed%22%2C%20it%20is%20only%20granted%20permissions%20%22Read%2C%20Write%20DAC%22.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAttached%20is%20a%20procmon%20trace%20showing%20this%20situation%2C%20the%20highlighted%20line%20being%20the%20case%20of%20opening%20the%20key%20from%20the%20redirected%20helium%20containerized%20registry.%26nbsp%3B%20In%20this%20case%2C%20the%20app%20examined%20the%20return%20permissions%20and%20gives%20up.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22TIMOTHYMANGAN_0-1651601025983.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F368928i200CCE51CAC9ED8A%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22TIMOTHYMANGAN_0-1651601025983.png%22%20alt%3D%22TIMOTHYMANGAN_0-1651601025983.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3355915%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3355915%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F146612%22%20target%3D%22_blank%22%3E%40TIMOTHY%20MANGAN%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThanks%20for%20reporting%20this.%20I%20would%20love%20to%20know%20a%20little%20more%20details%20about%20this%20issue%20(like%20App%20name%2C%20expected%20registry%20details%2C%20if%20it%20was%20previously%20installed%2C%20etc.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHowever%2C%20I%20have%20faced%20similar%20issues%20in%20the%20past%2C%20and%20found%20that%20(the%20workaround%20of)%20enabling%20the%20capability%20of%20'Run%20as%20administrator%20(restricted)'%20often%20resolves%20this%20issue.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Aniket_Banerjee_0-1652252494887.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F370674i068FB2627F86E9AF%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Aniket_Banerjee_0-1652252494887.png%22%20alt%3D%22Aniket_Banerjee_0-1652252494887.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20case%20this%20doesn't%20work%2C%20you%20can%20also%20try%20to%20run%20the%20(MSIX)%20application%20as%20an%20administrator%2C%20and%20it%20may%20resolve%20this%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3365900%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3365900%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20application%20is%20%22ExamDiff%22%20from%20PrestoSoft%20(a%20free%20product%20you%20can%20access%20from%20their%20website).%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20image%20I%20provided%20in%20the%20original%20post%20shows%20the%20line%20in%20a%20procmon%20trace%20that%20is%20problematic%20as%20the%20highlighted%20one%20(click%20on%20the%20image%20to%20view).%26nbsp%3B%20The%20test%20was%20on%20a%20clean%20VM%20that%20had%20never%20seen%20the%20product.%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20example%20was%20taken%20from%20a%20package%20that%20included%20the%20PSF%20RegLegacyFixup%20(which%20is%20needed%20because%20without%20it%20the%20app%20won't%20store%20user%20options%20in%20the%20registry%20at%20all).%20The%20result%20shows%20in%20the%20details%20column%20of%20procmon%20that%20%22Read%2C%20Write%20DAC%22%20permissions%20were%20granted.%20Instead%2C%20the%20result%20should%20say%20that%20%22Read%2FWrite%22%20permissions%20were%20granted%2C%20just%20like%20the%20call%20made%20against%20the%20parent%20key%206%20lines%20previous.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3369853%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3369853%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F146612%22%20target%3D%22_blank%22%3E%40TIMOTHY%20MANGAN%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWould%20it%20be%20possible%20for%20you%20to%20share%20the%20config.json%20for%20the%20PSF%20RegLegacyFixup%3F%20We%20can%20try%20to%20fix%20this%20manually.%20We'll%20share%20the%20fix%20if%20it%20works.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3372317%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3372317%22%20slang%3D%22en-US%22%3EBest%20method%20would%20be%20to%20send%20you%20the%20package.%20Give%20me%20a%20link%20to%20send%20it%20to%20you.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3379313%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3379313%22%20slang%3D%22en-US%22%3ETim%2C%20can%20you%20please%20send%20it%20to%20me%20as%20a%20Private%20Message%3F%20You%20can%20attach%20files%20upto%2070%20MB%20here.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3411517%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3411517%22%20slang%3D%22en-US%22%3E%3CP%3E%5Bpackage%20sent%20previously%5D%3CBR%20%2F%3E%3CBR%20%2F%3E%40Aniket_Banergee%20I%20have%20been%20doing%20some%20digging%20on%20another%20app%20with%20an%20issue%20using%20CreateKeyEx%20in%20a%20similar%20situation%20which%20may%20be%20interesting%20as%20well.%20In%20this%20similar%20case%2C%20the%20call%20requesting%20%22Maximum_Allowed%22%20permissions%20gets%20an%20access%20denied.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20this%20case%2C%20the%20caller%20first%20opens%20the%20HKCU%20key.%20%3CBR%20%2F%3EThen%20it%20calls%20CreateKeyEx%20using%20the%20returned%20HKCU%20key%20and%20a%20path%20%22Software%5C...%22%20which%20represents%20a%20key%20present%20in%20the%20package%2C%20the%20call%20to%20impl%3ACreateKeyEx%20is%20requesting%20Maximum_Allowed%20permissions%20and%20this%20call%20is%20successful.%20%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20app%20passes%20this%20package%20key%20to%20another%20CreateKeyEx%20call%20to%20create%20a%20subkey%20not%20present%20in%20the%20package.%20If%20I%20query%20the%20key%20passed%20by%20the%20app%20in%20using%20NTQueryKey%2C%20this%20shows%20the%20key%20path%20in%20the%20form%20%22%3D%5CREGISTRY%5CUSER%5C...%22.%20This%20CreateKeyEx%20call%20is%20the%20one%20returning%20ACCESS_DENIED%2C%20which%20is%20incorrect.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPS%3A%20I%20am%20testing%20against%20Windows%2010%2031H2%20(19044.1706)%20with%20May%202022%20updates.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3414003%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3414003%22%20slang%3D%22en-US%22%3EHi%20Tim%2C%3CBR%20%2F%3E%3CBR%20%2F%3EAcknowledging%20your%20post.%20This%20is%20more%20complicated%20than%20I%20initially%20anticipated.%20We%20are%20working%20on%20this%2C%20I'll%20let%20you%20know%20as%20soon%20as%20we%20find%20a%20solution%2C%20or%20if%20we%20need%20more%20details.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3414071%22%20slang%3D%22en-US%22%3ERe%3A%20MSIX%20Runtime%20HKCU%20CreateKey%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3414071%22%20slang%3D%22en-US%22%3EOK.%20I'll%20mention%20that%20while%20I%20haven't%20run%20this%20completely%20down%2C%20I%20increased%20some%20logging%20and%20I'm%20now%20believing%20that%20calls%20to%20OpenKeyEx%20and%20CreateKeyEx%20against%20keys%20that%20are%20in%20the%20package%20return%20the%20key%2C%20but%20the%20%22result%22%20value%20returned%20by%20the%20function%20is%20not%20always%200.%20Likely%20that%20when%20the%20native%20key%20of%20what%20would%20be%20the%20parent%20key%20requested%20by%20the%20app%20is%20not%20present%20on%20the%20system%20(but%20is%20in%20the%20package)%20the%20result%20value%20is%202.%20For%20keys%20the%20dev%20know%20were%20put%20down%20by%20the%20installer%20the%20dev%20may%20or%20may%20not%20look%20at%20that%20result%20value%20as%20long%20as%20the%20key%20is%20returned.%3C%2FLINGO-BODY%3E
MVP

If you have a package that contains the registry key

    HKEY_CURRENT_USER\Software\Vendor

And you run that package and it creates a subkey under Vendor named "Settings".

 

If the application calls CreateKey against the "Vendor" key requesting access "MaximumAllowed", it is granted permissions "Read/Write."

 

If the application calls CreateKey against "Settings" key requesting access "MaximumAllowed", it is only granted permissions "Read, Write DAC".

 

Attached is a procmon trace showing this situation, the highlighted line being the case of opening the key from the redirected helium containerized registry.  In this case, the app examined the return permissions and gives up.

 

TIMOTHYMANGAN_0-1651601025983.png

 

 

8 Replies

@TIMOTHY MANGAN

Thanks for reporting this. I would love to know a little more details about this issue (like App name, expected registry details, if it was previously installed, etc.

 

However, I have faced similar issues in the past, and found that (the workaround of) enabling the capability of 'Run as administrator (restricted)' often resolves this issue.

Aniket_Banerjee_0-1652252494887.png

 

In case this doesn't work, you can also try to run the (MSIX) application as an administrator, and it may resolve this issue.

The application is "ExamDiff" from PrestoSoft (a free product you can access from their website).

The image I provided in the original post shows the line in a procmon trace that is problematic as the highlighted one (click on the image to view).  The test was on a clean VM that had never seen the product.

This example was taken from a package that included the PSF RegLegacyFixup (which is needed because without it the app won't store user options in the registry at all). The result shows in the details column of procmon that "Read, Write DAC" permissions were granted. Instead, the result should say that "Read/Write" permissions were granted, just like the call made against the parent key 6 lines previous.

@TIMOTHY MANGAN

 

Would it be possible for you to share the config.json for the PSF RegLegacyFixup? We can try to fix this manually. We'll share the fix if it works.

Best method would be to send you the package. Give me a link to send it to you.
Tim, can you please send it to me as a Private Message? You can attach files upto 70 MB here.

[package sent previously]

@Aniket_Banergee I have been doing some digging on another app with an issue using CreateKeyEx in a similar situation which may be interesting as well. In this similar case, the call requesting "Maximum_Allowed" permissions gets an access denied.

In this case, the caller first opens the HKCU key.
Then it calls CreateKeyEx using the returned HKCU key and a path "Software\..." which represents a key present in the package, the call to impl:CreateKeyEx is requesting Maximum_Allowed permissions and this call is successful.

The app passes this package key to another CreateKeyEx call to create a subkey not present in the package. If I query the key passed by the app in using NTQueryKey, this shows the key path in the form "=\REGISTRY\USER\...". This CreateKeyEx call is the one returning ACCESS_DENIED, which is incorrect.

 

PS: I am testing against Windows 10 31H2 (19044.1706) with May 2022 updates.

Hi Tim,

Acknowledging your post. This is more complicated than I initially anticipated. We are working on this, I'll let you know as soon as we find a solution, or if we need more details.
OK. I'll mention that while I haven't run this completely down, I increased some logging and I'm now believing that calls to OpenKeyEx and CreateKeyEx against keys that are in the package return the key, but the "result" value returned by the function is not always 0. Likely that when the native key of what would be the parent key requested by the app is not present on the system (but is in the package) the result value is 2. For keys the dev know were put down by the installer the dev may or may not look at that result value as long as the key is returned.