CVE-2017-8715Corporation Device Guard vulnerability

4 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
1.9%
top 16.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 13

Description

The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Windows Security Feature Bypass".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-74pw-q437-p53q: The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it2022-05-13

📋Vendor Advisories

1
Microsoft
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability2017-10-10

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - October 20172017-10-10
CVE-2017-8715 — Corporation Device Guard vulnerability | cvebase