Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2019-0637
Published: February 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, when Windows is connected to both an ethernet and a cellular network. A remote attacker can bypass configured firewall policies and perform unauthorized actions against the affected system.
Note, this vulnerability cannot be triggered remotely.
Affected software
Windows Server