CVE-2017-0007HighCVSS 5.5

Device Guard Security Feature Bypass Vulnerability

Published
March 14, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass exists when Device Guard does not properly validate certain elements of a signed PowerShell script. An attacker who successfully exploited this vulnerability could modify the contents of a PowerShell script without invalidating the signature associated with the file. Because Device Guard relies on the signature to determine the script is non-malicious, Device Guard could then allow a malicious script to execute. In an attack scenario, an attacker could modify the contents of a PowerShell script without invalidating the signature associated with the file. The update addresses the vulnerability by correcting how Device Guard validates certain elements of signed PowerShell scripts.

🎯 Affected products8

  • Windows 10 Version 1511 for 32-bit Systems
  • Windows 10 Version 1511 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)

✅ Remediation

KB4013429 (Security Update) KB4012606 (Security Update) KB4013198 (Security Update)

🔗 References (7)