vendor:
Windows 10
by:
Google Security Research
5.5
CVSS
MEDIUM
Security Feature Bypass
264
CWE
Product Name: Windows 10
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2015-2553
CPE: cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
Platforms Tested: Windows 10
2015
Windows: Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux
The fix for CVE-2015-2553 can be bypassed to get limited mount reparse points working again for sandbox attacks. By abusing shadow object directories and creating a dummy directory that shadows GLOBAL??, an attacker can redirect a reparse point to an arbitrary location that they control.
Mitigation:
Unknown