vendor:
Windows
by:
Unknown
N/A
CVSS
N/A
Security Feature Bypass
Unknown
CWE
Product Name: Windows
Affected Version From: Windows 10 1809 (not tested earlier)
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Windows 10 1809 (not tested earlier), Windows 10 SMode (not tested)
Unknown
LUAFV NtSetCachedSigningLevel Device Guard Bypass
The NtSetCachedSigningLevel system call can be tricked by the operation of LUAFV to apply a cached signature to an arbitrary file leading to a bypass of code signing enforcement under UMCI with Device Guard. The exploit involves creating a file with the contents of a valid Microsoft signed file, virtualizing that file using LUAFV, copying an unsigned executable to the virtual store with the target virtualized name, and calling NtSetCachedSigningLevel on the virtualized file.
Mitigation:
Unknown