Hacker News new | ask | show | jobs
by drdexebtjl 28 days ago
I don’t think “only invoke MSI signed executables” inspires confidence either. There’s ought to be an MSI signed executable that launches arbitrary executables by design and defeats the mitigation.

The author got around a similar mitigation in their exploit for ASUS DriverHub (linked in the original article).

1 comments

Oh right, yes, either that, or one of them is bound to have a DLL hijack issue that can be taken advantage of.
Or just a TOCTOU race :)