Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2019-0637

 

Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2019-0637

Published: February 13, 2019


Vulnerability identifier: #VU17645
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0637
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, when Windows is connected to both an ethernet and a cellular network. A remote attacker can bypass configured firewall policies and perform unauthorized actions against the affected system.

Note, this vulnerability cannot be triggered remotely.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-0637

Install updates from vendor's website.


External References

Related Security Bulletins