CVE-2019-0732
HIGHWindows - Device Guard Bypass via LUAFV Driver Improper Call Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0732. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages the LUAFV driver and NtSetCachedSigningLevel to bypass Device Guard by tricking the signing process into applying a cached signature to an arbitrary unsigned file. It involves file virtualization and a race condition to bind the signature to the unsigned file.
Description
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
Exploits (1)
The exploit leverages the LUAFV driver and NtSetCachedSigningLevel to bypass Device Guard by tricking the signing process into applying a cached signature to an arbitrary unsigned file. It involves file virtualization and a race condition to bind the signature to the unsigned file.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H