Microsoft .NET Framework Device Guard CVE-2018-1039 Security Feature Bypass Vulnerability

description-logoDescription

A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine.

affected-products-logoAffected Applications

Microsoft .NET Framework 3.5 on Windows Server version 1709 (Server Core Installation)
Microsoft .NET Framework 3.5 on Windows Server version 1803 (Server Core Installation)
Microsoft .NET Framework 4.5.2 on Windows RT 8.1
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows RT 8.1
Microsoft .NET Framework 4.7.1 on Windows Server version 1709 (Server Core Installation)
Windows 10
Windows 7
Windows 8
Windows Server 2008
Windows Server 2012
Windows Server 2016

CVE References

CVE-2018-1039