SB2018081435 - Windows lockscreen bypass in Cortana
Published: August 14, 2018
Security Bulletin ID
SB2018081435
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Physical access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-8253)
The vulnerability allows a local attacker to bypass lockscreen.
The vulnerability exists within Microsoft Cortana code that allows arbitrary website browsing on the lockscreen. A user with physical access to device can access vimctim's browser and steal browser stored passwords or log on to websites as another user.
Successful exploitation of the vulnerability requires access to the console and the system must have Microsoft Cortana assistance enabled.
Remediation
Install update from vendor's website.