Intrusion Prevention

MS.Windows.Device.Guard.Security.Bypass

Description

This indicates an attack attempt to exploit a Security Bypass vulnerability in Microsoft Windows.
The vulnerability is due to an error when the vulnerable software attempts to handles maliciously crafted script. An attacker can exploit this by tricking a user into opening a malicious script and bypass signature checking within the context of the process.

Affected Products

Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 1511 for 32-bit Systems
Windows 10 Version 1511 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows Server 2016 for x64-based Systems
Windows Server 2016 for x64-based Systems
(Server Core installation)

Impact

Security Bypass: Remote attackers can bypass security mechanism on vulnerable systems

Recommended Actions

Apply the most recent upgrade or patch from the vendor
http://technet.microsoft.com/security/bulletin/MS17-012

CVE References

CVE-2017-0007