Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Smoke and Mirrors: Windows Driver Signatures Are Optional

Recon Conference via YouTube

Overview

Coursera Plus Monthly Sale: All Certificates & Courses 40% Off!
A conference talk from Recon2024 where Gabriel Landau, a principal at Elastic Security, reveals a previously-unnamed vulnerability class in Windows that allows bypassing Driver Signing Enforcement (DSE). Discover how incorrect assumptions in Windows' core design lead to security vulnerabilities that enable arbitrary code execution with kernel privileges. Learn about the history of this vulnerability class and see a live demonstration of exploiting Windows 11 to load unsigned drivers without using third-party code like Bring-Your-Own-Vulnerable-Drivers. The presentation covers potential fixes for this vulnerability, detection methods for defenders, and includes the release of a tool demonstrating the DSE exploit alongside a mitigation solution. Understand how this vulnerability class extends beyond Windows to affect any software relying on documented Windows behavior, with implications for both user and kernel-mode applications.

Syllabus

Recon2024 - Gabriel Landau - Smoke And Mirrors Driver Signatures Are Optional

Taught by

Recon Conference

Reviews

Start your review of Smoke and Mirrors: Windows Driver Signatures Are Optional

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.