PT-2017-18494 · Microsoft · Device Guard+4
Published
2017-10-10
·
Updated
2019-10-03
·
CVE-2017-8715
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10 versions 10 Gold, 1511, 1607, and 1703
Windows Server 2016
Description
A security feature bypass issue exists in the way Microsoft Device Guard handles Windows PowerShell sessions. This allows attackers to bypass security features and potentially affect the system.
Recommendations
For Microsoft Windows 10 versions 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, consider restricting access to Windows PowerShell sessions as a temporary mitigation measure until a fix is available.
As a workaround, restrict the use of Windows PowerShell to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Device Guard
Windows 10
Windows
Windows Powershell
Windows Server 2016