CVE-2017-0007Improper Input Validation in Corporation Device Guard

Severity
5.5MEDIUMNVD
EPSS
1.2%
top 20.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDmicrosoft/windows_101511, 1607+1
CVEListV5microsoft_corporation/device_guardDevice Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g66p-2m7v-98p3: Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidatin2022-05-17
Kernel
bpf: fix incorrect tracking of register size truncation2017-12-18

📋Vendor Advisories

1
Microsoft
Device Guard Security Feature Bypass Vulnerability2017-03-14

💬Community

1
Bugzilla
CVE-2017-2641 CVE-2017-2643 CVE-2017-2644 CVE-2017-2645 moodle: Multiple security vulnerabilities2017-03-22
CVE-2017-0007 — Improper Input Validation | cvebase