CVE-2019-7651
EPP.sys in Emsisoft Anti-Malware 2018.8.1.8923 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the .EPP device are not properly protected, leading to unintended impersonation or object creation.
Source: CVE-2019-7651