SB2018041033 - Security restrictions bypass in Microsoft Device Guard



SB2018041033 - Security restrictions bypass in Microsoft Device Guard

Published: April 10, 2018

Security Bulletin ID SB2018041033
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security Feature Bypass (CVE-ID: CVE-2018-0966)

The vulnerability allows a remote attacker to bypass antimalware protection.

The vulnerability exists in the Device Guard when processing files. A remote attacker can create a specially crafted file that appears to be signed for the application.

Successful exploitation of the vulnerability may allow an attacker to bypass Device Guard protection and execute malicious file on the system.

Remediation

Install update from vendor's website.