PT-2017-3124 · Microsoft · Device Guard+4

Published

2017-10-10

·

Updated

2019-10-03

·

CVE-2017-11823

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 versions Gold, 1511, 1607, and 1703 Windows Server 2016
Description The issue is related to how Microsoft Device Guard handles Windows PowerShell sessions, allowing a security feature bypass. This is due to insufficient access restrictions in the Microsoft Device Guard component, which is responsible for protecting the integrity of hardware and software. An attacker, acting locally, can exploit this issue to bypass integrity checks and inject malicious code into a trusted PowerShell process.
Recommendations For Microsoft Windows 10 versions Gold, 1511, 1607, and 1703: Update to a version that includes the fix for this security feature bypass issue. For Windows Server 2016: Apply the necessary security updates to resolve the issue. As a temporary workaround, consider restricting access to Windows PowerShell sessions to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02524
CVE-2017-11823

Affected Products

Device Guard
Windows 10
Windows
Windows Powershell
Windows Server 2016