PT-2020-3927 · Microsoft+1 · Windows Defender Application Control+3
Published
2020-09-08
·
Updated
2025-09-04
·
CVE-2020-0951
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Windows Defender Application Control (WDAC) (affected versions not specified)
Description:
A security feature bypass issue exists in Windows Defender Application Control (WDAC), allowing an attacker to bypass WDAC enforcement and execute arbitrary code by sending commands to a PowerShell session. To exploit this issue, an attacker needs administrator access on a local machine where PowerShell is running. The vulnerability is related to errors in validating PowerShell commands.
Recommendations:
To resolve the issue, apply the update that corrects how PowerShell commands are validated when WDAC protection is enabled.
As a temporary workaround, consider restricting access to PowerShell sessions to minimize the risk of exploitation.
Avoid using PowerShell commands that could be used to execute arbitrary code until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Powershell
Windows
Windows Defender Application Control