g_CiOptions in a Virtualized World
ID: a93b09d0-562a-592d-806f-b1a881fcf0cf
STIX ID: report--a93b09d0-562a-592d-806f-b1a881fcf0cf
Feed Name: XPN Infosec Blog
This report demonstrates multiple kernel-level techniques an attacker can use to disable Windows Driver Signature Enforcement (DSE) — including patching CI.dll's CiValidateImageHeader by flipping PTE bits and using either a malicious signed driver or a vulnerable driver (e.g., iqvw64e.sys) to obtain read/write primitives. It explains how Virtualization Based Security (VBS) and Kernel Data Protection (KDP) limit direct modification of configuration variables like g_CiOptions, shows how attackers can instead patch policy-check functions to return success, and discusses how HVCI and Microsoft Attack Surface Reduction can mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
