PT-2017-3124 · Microsoft · Device Guard+4

Publicado

2017-10-10

·

Atualizado

2019-10-03

·

CVE-2017-11823

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 versions Gold, 1511, 1607, and 1703 Windows Server 2016
Description The issue is related to how Microsoft Device Guard handles Windows PowerShell sessions, allowing a security feature bypass. This is due to insufficient access restrictions in the Microsoft Device Guard component, which is responsible for protecting the integrity of hardware and software. An attacker, acting locally, can exploit this issue to bypass integrity checks and inject malicious code into a trusted PowerShell process.
Recommendations For Microsoft Windows 10 versions Gold, 1511, 1607, and 1703: Update to a version that includes the fix for this security feature bypass issue. For Windows Server 2016: Apply the necessary security updates to resolve the issue. As a temporary workaround, consider restricting access to Windows PowerShell sessions to minimize the risk of exploitation.

Exploit

Correção

Race Condition

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02524
CVE-2017-11823

Produtos afetados

Device Guard
Windows 10
Windows
Windows Powershell
Windows Server 2016