Description
Detects the exploitation of CVE-2018-8411 and CVE-2019-1170, privilege escalation flaws in Windows NTFS handling. The rule matches the crafted file operations that public exploits use to corrupt the filesystem driver's memory.
3 SIDs: 48057, 200124, 200343
Detects the exploitation of CVE-2018-8411 and CVE-2019-1170, privilege escalation flaws in Windows NTFS handling. The rule matches the crafted file operations that public exploits use to corrupt the filesystem driver's memory.