#VU19320 Improper access control in System.Management.Automation - CVE-2019-1167
Published: July 24, 2019 / Updated: July 24, 2019
System.Management.Automation
Microsoft
Description
The vulnerability allows a local attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions in Windows Defender Application Control (WDAC). A local administrator can bypass WDAC enforcement, circumvent PowerShell Core Constrained Language Mode on the machine and access resources in an unintended way.