Attackers can create recursive NTFS junctions that point back to a parent directory, generating infinite file paths. This technique, called GhostTree, causes scanning tools including EDR products to follow the loop indefinitely. Malicious files in the same folder remain unexamined because the scanner never finishes.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
CISA Adds Cisco, Chrome, Arista Flaws to KEV Catalog