#VU13309 Security feature bypass in Windows and Windows Server - CVE-2018-8201
Published: June 12, 2018 / Updated: June 12, 2018
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Device Guard allows a local user to inject malicious code into a Windows PowerShell session. A local attacker can bypass Device Guard Code Integrity policy and execute arbitrary code on the target system with escalated privileges.