Microsoft Windows CiSetFileCache TOCTOU Incomplete Fix

Discussion in 'News Aggregator' started by Packet Storm, 18 Apr 2018.

  1. Packet Storm

    Packet Storm Guest

    The fix for CVE-2017-11830 is insufficient to prevent a normal user application adding a cached signing level to an unsigned file by exploiting a TOCTOU in CI leading to circumventing Device Guard policies.

    Continue reading...
     

Share This Page

Loading...