vendor:
by:
N/A
CVSS
N/A
Security Feature Bypass
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE: CVE-2015-2553
CPE:
Platforms Tested: Windows 8.1
Windows: Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux 2
The fix for CVE-2015-2553 can be bypassed to get limited mount reparse points working again for sandbox attacks by abusing anonymous token impersonation.
Mitigation:
This could be fixed by passing the OBJ_IGNORE_IMPERSONATED_DEVICEMAP flag when checking for the writable directory, or the anonymous authentication ID shouldn’t create a per-user device map.