I've now seen different things on whether enabling Sandbox or WDAG suffices to make a machine vulnerable to this System32 file write EoP. Can anyone clarify?https://twitter.com/BleepinComputer/status/1303030451230199810 …
-
-
Thanks. Appreciate the response. I was under the impression your test device was vulnerable because it had the full Hyper-V role enabled. But if it was because Sandbox was enabled then I'd definitely go with the operating assumption that WDAG for Edge is sufficient as well.
-
And if Sandbox and WDAG are sufficient...that brings a lot of security-conscious people or organizations who are using those some bad news. Because of a lot of them may be using application control except with programs in SYSTEM32 allowed.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
