Improper access control in System.Management.Automation - CVE-2019-1167

 

Improper access control in System.Management.Automation - CVE-2019-1167

Published: July 24, 2019 / Updated: July 24, 2019


Vulnerability identifier: #VU19320
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1167
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions in Windows Defender Application Control (WDAC). A local administrator can bypass WDAC enforcement, circumvent PowerShell Core Constrained Language Mode on the machine and access resources in an unintended way.


Affected software

System.Management.Automation
PowerShell Core

How to mitigate CVE-2019-1167

Install updates from vendor's website.

System.Management.Automation - addressed in versions 6.1.5, 6.2.2

External References

Related Security Bulletins