CVE-2019-0627HighCVSS 5.3
Windows Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how Windows validates User Mode Code Integrity policies.
🎯 Affected products23
- PowerShell Core 6.1
- PowerShell Core 6.2
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1703 for 32-bit Systems
- Windows 10 Version 1703 for x64-based Systems
- Windows 10 Version 1709 for 32-bit Systems
- Windows 10 Version 1709 for ARM64-based Systems
- Windows 10 Version 1709 for x64-based Systems
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1709 (Server Core Installation)
- Windows Server, version 1803 (Server Core Installation)
✅ Remediation
KBRelease Notes (Security Update) KB4487020 (Security Update) KB4487017 (Security Update) KB4486996 (Security Update) KB4487018 (Security Update) KB4487026 (Security Update) KB4487044 (Security Update)
🔗 References (14)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0627
- patchhttps://github.com/PowerShell/PowerShell#get-powershell
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4487020
- referencehttps://support.microsoft.com/help/4487020
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4487017
- referencehttps://support.microsoft.com/help/4487017
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4486996
- referencehttps://support.microsoft.com/help/4486996
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4487018
- referencehttps://support.microsoft.com/help/4487018
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4487026
- referencehttps://support.microsoft.com/help/4487026
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4487044
- referencehttps://support.microsoft.com/help/4487044