Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2018-8222

 

Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2018-8222

Published: July 10, 2018 / Updated: July 10, 2018


Vulnerability identifier: #VU13790
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8222
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists in Device Guard due to improper exposure of functions and processes user supplied code. A local attacker can inject code into a trusted PowerShell process, run it with the same trust level as the script and bypass the Device Guard Code Integrity policy on the local machine.




Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-8222

Install updates from vendor's website.


External References

Related Security Bulletins