logo

g_CiOptions in a Virtualized World

ID: a93b09d0-562a-592d-806f-b1a881fcf0cf

STIX ID: report--a93b09d0-562a-592d-806f-b1a881fcf0cf

Feed Name: XPN Infosec Blog

Threat Score
75/100

Date Published: 2022-05-15

Date Updated: 2026-07-30

...
...

This report demonstrates multiple kernel-level techniques an attacker can use to disable Windows Driver Signature Enforcement (DSE) — including patching CI.dll's CiValidateImageHeader by flipping PTE bits and using either a malicious signed driver or a vulnerable driver (e.g., iqvw64e.sys) to obtain read/write primitives. It explains how Virtualization Based Security (VBS) and Kernel Data Protection (KDP) limit direct modification of configuration variables like g_CiOptions, shows how attackers can instead patch policy-check functions to return success, and discusses how HVCI and Microsoft Attack Surface Reduction can mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.