Microsoft .NET Framework Device Guard CVE-2018-1039 Security Feature Bypass Vulnerability
Description
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine.
Affected Applications
Microsoft .NET Framework 3.5 on Windows Server version 1709 (Server Core Installation)
Microsoft .NET Framework 3.5 on Windows Server version 1803 (Server Core Installation)
Microsoft .NET Framework 4.5.2 on Windows RT 8.1
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows RT 8.1
Microsoft .NET Framework 4.7.1 on Windows Server version 1709 (Server Core Installation)
Windows 10
Windows 7
Windows 8
Windows Server 2008
Windows Server 2012
Windows Server 2016