CVE-2018-8129: Medium severity Microsoft Windows 10 vulnerability
Published May 9, 2018
·Updated
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8132.
Affected Software
8 affected components
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
Microsoft Windows Server 2016=1709
Microsoft Windows Server 2016=1803
Remediation
Event History
May 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. User interaction is not required.
2
Which systems are identified as affected?
The affected products listed are Microsoft Windows 10 and Microsoft Windows Server 2016, including Windows 10 Servers as described in the advisory summary.
3
What is the likely impact if exploitation succeeds?
An attacker could bypass Device Guard. The CVSS vector also rates confidentiality, integrity, and availability impact as low.
4
Is a fix available?
Yes. A patch is available.