Microsoft Windows LUAFV NtSetCachedSigningLevel Device Guard Bypass

On Microsoft Windows, the NtSetCachedSigningLevel system call can be tricked by the operation of LUAFV to apply a cached signature to an arbitrary file leading to a bypass of code signing enforcement under UMCI with Device Guard.


MD5 | c842665e8c982e999825c50d9c78df7a


Related Posts