Endpoint Vulnerability

Microsoft: Device Guard Security Feature Bypass Vulnerability

Description

A security feature bypass exists when Device Guard incorrectly validates an untrusted file. An attacker who successfully exploited this vulnerability could make an unsigned file appear to be signed. Because Device Guard relies on the signature to determine the file is non-malicious, Device Guard could then allow a malicious file to execute.

Affected Products

Windows 10,Windows Server 2016,Windows Server, version 1709 (Server Core Installation)

References

CVE-2018-0966,