Microsoft Windows LUAFV NtSetCachedSigningLevel Device Guard Bypass

On Microsoft Windows, the NtSetCachedSigningLevel system call can be tricked by the operation of LUAFV to apply a cached signature to an arbitrary file leading to a bypass of code signing enforcement under UMCI with Device Guard.

Leave a Reply