Microsoft Windows CI CiSetFileCache TOCTOU Security Feature Bypass
Posted by deepcore on November 22, 2017 – 9:43 pm
It is possible to add a cached signing level to an unsigned file by exploiting a TOCTOU in CI leading to circumvention of Device Guard policies and possibly PPL signing levels.
Post a reply
You must be logged in to post a comment.