CVE-2018-8217: Medium severity Microsoft Windows 10 vulnerability
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8221.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
What is the practical impact of successful exploitation?
An attacker could bypass Device Guard code integrity protections and inject malicious code into a Windows PowerShell session. The CVSS assessment indicates low impact to confidentiality, integrity, and availability.
Which systems should be prioritized for remediation?
Systems running Windows 10 or Windows Server 2016 are identified as affected. Apply the available patch, with particular attention to endpoints and servers where Device Guard and PowerShell are in use.