CVE-2018-8132: Medium severity Microsoft Windows 10 vulnerability
Published May 9, 2018
·Updated
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8129.
Affected Software
8 affected components
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
Microsoft Windows Server 2016=1709
Microsoft Windows Server 2016=1803
Remediation
Event History
May 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Systems running Microsoft Windows 10 or Windows Server 2016 are listed as affected. The issue concerns bypassing the Device Guard security feature.
2
What level of access does an attacker need?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
3
What is the potential impact if exploited?
An attacker could bypass Device Guard. The CVSS metrics indicate low impacts to confidentiality, integrity, and availability.
4
Is a fix available?
Yes. A patch is available.