Microsoft Windows LUAFV NtSetCachedSigningLevel Device Guard Bypass
Posted by deepcore on April 18, 2019 – 2:30 am
On Microsoft Windows, the NtSetCachedSigningLevel system call can be tricked by the operation of LUAFV to apply a cached signature to an arbitrary file leading to a bypass of code signing enforcement under UMCI with Device Guard.
Post a reply
You must be logged in to post a comment.