Microsoft Windows suffers from a CiSetFileCache TOCTOU CVE-2017-11830 variant WDAC security feature bypass vulnerability.
eb52dc13fee602e4f4367c0eb42d933defb5c0336c73d90ce5236346a9ec00ba
The fix for CVE-2017-11830 is insufficient to prevent a normal user application adding a cached signing level to an unsigned file by exploiting a TOCTOU in CI leading to circumventing Device Guard policies.
8bf899b59331805e3565783c1df52349bae6d10f5374cb34ff520b4495773303
It is possible to add a cached signing level to an unsigned file by exploiting a TOCTOU in CI leading to circumvention of Device Guard policies and possibly PPL signing levels.
10740234534d576953b78d366019b0eaed2b7e2f77b447ea307edd5c886a5515