CVE-2018-1039 Information

Description

A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard aka .NET Framework Device Guard Security Feature Bypass Vulnerability.\ This affects Microsoft .NET Framework 4.7.1 Microsoft .NET Framework 4.6 Microsoft .NET Framework 3.5 Microsoft .NET Framework 4.7/4.7.1 Microsoft .NET Framework 3.0 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 4.6.2/4.7/4.7.1 Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1 Microsoft .NET Framework 2.0 Microsoft .NET Framework 4.6/4.6.1/4.6.2.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.securityfocus.com/bid/104072 http://www.securitytracker.com/id/1040851 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1039

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: