Closed GoogleCodeExporter closed 9 years ago
Assigned MSRC case number 30502
Original comment by fors...@google.com
on 23 Jun 2015 at 4:54
This functionality has been fixed in build 10158. The silo objects have been
merged into job objects and a TCB privilege check placed around the setting of
the root directory. However until it can be determined how to use this
functionality we can't say for certain that it's not possible for a user
application to ask for a silo'ed process to be created and the directory object
isn't secure.
Marking as Invalid but not opened yet until verified that the final RTM build
is definitely not vulnerable.
Original comment by fors...@google.com
on 1 Jul 2015 at 10:07
Removed view restriction.
Original comment by fors...@google.com
on 8 Sep 2015 at 2:57
Original issue reported on code.google.com by
fors...@google.com
on 23 Jun 2015 at 1:40Attachments: