PT-2017-3124 · Microsoft · Device Guard+4
Published
2017-10-10
·
Updated
2019-10-03
·
CVE-2017-11823
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10 versions Gold, 1511, 1607, and 1703
Windows Server 2016
Description
The issue is related to how Microsoft Device Guard handles Windows PowerShell sessions, allowing a security feature bypass. This is due to insufficient access restrictions in the Microsoft Device Guard component, which is responsible for protecting the integrity of hardware and software. An attacker, acting locally, can exploit this issue to bypass integrity checks and inject malicious code into a trusted PowerShell process.
Recommendations
For Microsoft Windows 10 versions Gold, 1511, 1607, and 1703: Update to a version that includes the fix for this security feature bypass issue.
For Windows Server 2016: Apply the necessary security updates to resolve the issue.
As a temporary workaround, consider restricting access to Windows PowerShell sessions to minimize the risk of exploitation.
Exploit
Fix
Race Condition
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Device Guard
Windows 10
Windows
Windows Powershell
Windows Server 2016