CVE-2018-8449
LOWWindows 10 and Windows Server 2016 - Security Feature Bypass via Device Guard File Validation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8449. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a TOCTOU (Time-of-Check Time-of-Use) race condition in the Windows Cache Manager to bypass WDAC (Windows Defender Application Control) by manipulating file cache signing levels via NtCreateSection. It involves an oplock-based race to replace a signed file with an unsigned one while the cache is being set.
Description
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Exploits (1)
This exploit leverages a TOCTOU (Time-of-Check Time-of-Use) race condition in the Windows Cache Manager to bypass WDAC (Windows Defender Application Control) by manipulating file cache signing levels via NtCreateSection. It involves an oplock-based race to replace a signed file with an unsigned one while the cache is being set.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N