PT-2020-3927 · Microsoft+1 · Windows Defender Application Control+3

Published

2020-09-08

·

Updated

2025-09-04

·

CVE-2020-0951

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Windows Defender Application Control (WDAC) (affected versions not specified)
Description: A security feature bypass issue exists in Windows Defender Application Control (WDAC), allowing an attacker to bypass WDAC enforcement and execute arbitrary code by sending commands to a PowerShell session. To exploit this issue, an attacker needs administrator access on a local machine where PowerShell is running. The vulnerability is related to errors in validating PowerShell commands.
Recommendations: To resolve the issue, apply the update that corrects how PowerShell commands are validated when WDAC protection is enabled. As a temporary workaround, consider restricting access to PowerShell sessions to minimize the risk of exploitation. Avoid using PowerShell commands that could be used to execute arbitrary code until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1272
ALT-PU-2022-1360
BDU:2020-04320
BIT-POWERSHELL-2020-0951
CVE-2020-0951

Affected Products

Alt Linux
Powershell
Windows
Windows Defender Application Control