CVE-2018-8216: Medium severity Microsoft Windows 10 vulnerability
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-8215, CVE-2018-8217, CVE-2018-8221.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is locally exploitable and requires low-privileged access. It does not require user interaction.
What is the potential impact of successful exploitation?
An attacker could bypass a Device Guard security feature and inject malicious code into a Windows PowerShell session. The CVSS vector indicates low impacts to confidentiality, integrity, and availability.
Which systems should be prioritized for remediation?
Systems running Windows 10 or Windows Server 2016 should be prioritized, particularly where Device Guard and PowerShell sessions are used. A patch is available.