30 Jan 18 06:04
Gabriel Bercea
Join Date: 03 Mar 2008
Where is SEC_IMAGE AllocationAttribute ?

I may be asking a stupid question but I believe that AllocationAttributes such as SEC_IMAGE are not present in the minifilter callbacks such as AcquireForSectionSynchronization. If I am correct than this is pretty sad for security developers, since you can run a process that has been opened with PAGE_READONLY but with SEC_IMAGE set. Not going into too many details but such techniques are already used in process doppelganging attacks and similar class of attacks. I am wondering, if I am right, is anywone from MSFT going to add these flags in some patch to Filter Manager ? Thanks, Gabriel
