CVE-2018-0966
LOWWindows 10 and Windows Server 2016 - Device Guard Security Feature Bypass via TOCTOU Race Condition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-0966. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a TOCTOU (Time-of-Check to Time-of-Use) vulnerability in Windows 10 1709 to bypass Device Guard policies by manipulating file handles and cached signing levels. The PoC demonstrates how an unsigned executable can be falsely signed by exploiting insufficient access checks in the CiSetFileCache function.
Description
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Exploits (1)
This exploit leverages a TOCTOU (Time-of-Check to Time-of-Use) vulnerability in Windows 10 1709 to bypass Device Guard policies by manipulating file handles and cached signing levels. The PoC demonstrates how an unsigned executable can be falsely signed by exploiting insufficient access checks in the CiSetFileCache function.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N