I couldn't find much information about Untrusted integrity level in Windows, and have some questions about it:
- Is there a place where an untrusted integrity level process can create named objects? (mutexes, events, etc..)
- Should untrusted integrity level process be able to open an existing named object, that was given a security descriptor in it's creation time with
ACEwithSYSTEM_MANDATORY_LABEL_NO_WRITE_UPtoMandatoryLevelUntrusted? When I try it, it fails with0xc0000022(access denied), while withMandatoryLevelLowit works great. - How do usually untrusted integrity processes communicate with their broker process? (like how does a google chrome tab communicates with the google chrome broker?)