SB2018041033 - Security restrictions bypass in Microsoft Device Guard
Published: April 10, 2018
Security Bulletin ID
SB2018041033
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security Feature Bypass (CVE-ID: CVE-2018-0966)
The vulnerability allows a remote attacker to bypass antimalware protection.The vulnerability exists in the Device Guard when processing files. A remote attacker can create a specially crafted file that appears to be signed for the application.
Successful exploitation of the vulnerability may allow an attacker to bypass Device Guard protection and execute malicious file on the system.
Remediation
Install update from vendor's website.