Microsoft Windows WFP Default Rules AppContainer Capability Bypass Privilege Escalation
Posted by deepcore on July 21, 2021 – 4:27 am
The default rules for the WFP connect layers permit certain executables to connect TCP sockets in AppContainers without capabilities leading to elevation of privilege.
Post a reply
You must be logged in to post a comment.