Anti-Virus Privileged File Write...

- AV AC AU C I A
发布: 2017-11-15
修订: 2025-04-13

Anti-Virus solutions are split into several different components (an unprivileged user mode part, a privileged user mode part and a kernel component). Logically the different systems talk to each other. By abusing NTFS directory junctions it is possible from the unprivileged user mode part ("the UI") to restore files from the virus quarantine with the permissions of the privileged user mode part ("Windows service"). This may results in a privileged file write vulnerability.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息