CVE-2019-1167
published 2019-07-19CVE-2019-1167: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka…
PriorityP417medium4.1CVSS 3.0
AVLACHPRHUINSUCHINAN
EPSS
1.10%
61.8th percentile
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powershell_core | — | — |
| microsoft | powershell_core | — | — |
| msrc | powershell_core_6.1 | — | — |
| msrc | powershell_core_6.2 | — | — |
CVSS provenance
nvdv3.04.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
ghsa4.1MEDIUM
osv4.1MEDIUM
vendor_msrc4.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
System.Management.Automation subject to bypass via script debugging
osv·2019-07-17·CVSS 4.1
CVE-2019-1167 [MEDIUM] System.Management.Automation subject to bypass via script debugging
System.Management.Automation subject to bypass via script debugging
## Microsoft Security Advisory CVE-2019-1167: Windows Defender Application Control Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2019-1167: Windows Defender Application Control Security Feature Bypass Vulnerability
## Executive Summary
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement.
An attacker who successfully exploited this vulnerability could circumvent PowerShell Core Constrained Language Mode on the machine.
To exploit the vulnerability,
an attacker would first have access to the local machine where PowerShell is running in Constrained Language mode.
By doing that an attacker could lev
GHSA
System.Management.Automation subject to bypass via script debugging
ghsa·2019-07-17·CVSS 4.1
CVE-2019-1167 [MEDIUM] System.Management.Automation subject to bypass via script debugging
System.Management.Automation subject to bypass via script debugging
## Microsoft Security Advisory CVE-2019-1167: Windows Defender Application Control Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2019-1167: Windows Defender Application Control Security Feature Bypass Vulnerability
## Executive Summary
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement.
An attacker who successfully exploited this vulnerability could circumvent PowerShell Core Constrained Language Mode on the machine.
To exploit the vulnerability,
an attacker would first have access to the local machine where PowerShell is running in Constrained Language mode.
By doing that an attacker could lev
Microsoft
Windows Defender Application Control Security Feature Bypass Vulnerability
vendor_msrc·2019-07-09·CVSS 4.1
CVE-2019-1167 [MEDIUM] Windows Defender Application Control Security Feature Bypass Vulnerability
Windows Defender Application Control Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could circumvent PowerShell Core Constrained Language Mode on the machine.
To exploit the vulnerability, an attacker would first have administrator access to the local machine where PowerShell is running in Constrained Language mode. By doing that an attacker could access resources in an unintended way.
The update addresses the vulnerability by correcting how PowerShell functions in Constrained Language Mode.
Microsoft PowerShell: Microsoft PowerShell
Microsoft: Microsoft
Impact: Security Feat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-19
Published