SB2018081435 - Windows lockscreen bypass in Cortana



SB2018081435 - Windows lockscreen bypass in Cortana

Published: August 14, 2018

Security Bulletin ID SB2018081435
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2018-8253)

The vulnerability allows a local attacker to bypass lockscreen.

The vulnerability exists within Microsoft Cortana code that allows arbitrary website browsing on the lockscreen. A user with physical access to device can access vimctim's browser and steal browser stored passwords or log on to websites as another user.

Successful exploitation of the vulnerability requires access to the console and the system must have Microsoft Cortana assistance enabled.

Remediation

Install update from vendor's website.