MS.WDK.Device.Meta.Data.Wizard.Code.Execution

description-logoDescription

This indicates an attack attempt to exploit a Code Execution vulnerability in MS WDK.
The vulnerability, which is located in the "devicemetadatawizard.exe" of WDK, can be exploited through misuse of a vulnerable method. An attacker can exploit this by tricking an unsuspecting user into open a malicious multiple-locale device manifest package and execute arbitrary code within the context of the application.

affected-products-logoAffected Products

Microsoft WDK

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch or updates available for this issue.
Do not open any untrusted devicemanifest-ms or devicemetadata-ms file.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-02-19 14.556 Default_action:pass:drop
2019-02-01 14.540