CVE-2018-8212: Medium severity Microsoft Windows 10 vulnerability
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs local access and low privileges on the affected system. No user interaction is required.
Can this be exploited remotely?
The CVSS vector identifies the attack vector as local, so the provided data does not indicate remote exploitation.
What is the likely security impact after exploitation?
An attacker could inject malicious code into a Windows PowerShell session. The CVSS assessment indicates low impact to confidentiality, integrity, and availability.
What remediation is available?
A patch is available for this vulnerability.