Microsoft Device Guard CVE-2018-8449 Security Feature Bypass Vulnerability

description-logoDescription

A security feature bypass exists when Device Guard incorrectly validates an untrusted file. An attacker who successfully exploited this vulnerability could make an unsigned file appear to be signed. Because Device Guard relies on the signature to determine the file is non-malicious, Device Guard could then allow a malicious file to execute. In an attack scenario, an attacker could make an untrusted file appear to be a trusted file. The update addresses the vulnerability by correcting how Device Guard handles untrusted files.

affected-products-logoAffected Applications

Windows 10
Windows Server 2016
Windows Server version 1803 (Server Core Installation)
Windows Server version 1709 (Server Core Installation)

CVE References

CVE-2018-8449