upvote
Reaching into ring -2 or the TPM allows privilege escalations past traditional "root permissions" and lets attackers defeat the sort of tamper protection that's designed to make escalations to local root manageable. Wipe-resistant malware, falsified cryptographic attestations, all sorts of fun.
reply
This is more about getting at the code that device manufacturers attempt to hide from the end user. Platform keys, secure enclaves, etc...
reply
Yep, I believe so
reply
But it supercharges what can be done once you get root, no?
reply
By a LOT. It would expose the data Windows keeps isolated using virtualization based security.
reply
Does this mean the exploit can be used in a VM to get access to the host machine?
reply