CVE-2018-8417
published 2018-11-14CVE-2018-8417: A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security…
PriorityP425medium5.3CVSS 3.0
AVLACLPRLUINSUCLILAL
EPSS
2.00%
78.5th percentile
A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft JScript Security Feature Bypass Vulnerability
vendor_msrc·2018-11-13·CVSS 4.5
CVE-2018-8417 [MEDIUM] Microsoft JScript Security Feature Bypass Vulnerability
Microsoft JScript Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard.
To exploit the vulnerability, an attacker would first have to access the local machine, and run a specially crafted application to create arbitrary COM objects.
The update addresses the vulnerability by correcting how Microsoft JScript manages COM object creation.
Microsoft JScript: Microsoft JScript
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search
GHSA
GHSA-v9q5-95vx-2g47: A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Securi
ghsa_unreviewed·2022-05-13
CVE-2018-8417 [MEDIUM] GHSA-v9q5-95vx-2g47: A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Securi
A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105795http://www.securitytracker.com/id/1042120https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8417http://www.securityfocus.com/bid/105795http://www.securitytracker.com/id/1042120https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8417
2018-11-14
Published