dotnet: Device Guard security bypass can allow for privilege escalation
Published May 9, 2018
7.8
HIGHCVSS 3.0
EPSS 1.32%
Description
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Affected products
-
- Version 2.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2StatusaffectedConstraints-
- Version 2.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2StatusaffectedConstraints-
- Version 2.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2StatusaffectedConstraints-
- Version 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2StatusaffectedConstraints-
- Version 3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2StatusaffectedConstraints-
- Version 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2StatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1607 for 32-bit SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1607 for x64-based SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1703 for 32-bit SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1703 for x64-based SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1709 for 32-bit SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1709 for x64-based SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1803 for 32-bit SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 Version 1803 for x64-based SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 for 32-bit SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 10 for x64-based SystemsStatusaffectedConstraints-
- Version 3.5 on Windows 8.1 for 32-bit systemsStatusaffectedConstraints-
- Version 3.5 on Windows 8.1 for x64-based systemsStatusaffectedConstraints-
- Version 3.5 on Windows Server 2012StatusaffectedConstraints-
- Version 3.5 on Windows Server 2012 (Server Core installation)StatusaffectedConstraints-
- Version 3.5 on Windows Server 2012 R2StatusaffectedConstraints-
- Version 3.5 on Windows Server 2012 R2 (Server Core installation)StatusaffectedConstraints-
- Version 3.5 on Windows Server 2016StatusaffectedConstraints-
- Version 3.5 on Windows Server 2016 (Server Core installation)StatusaffectedConstraints-
- Version 3.5 on Windows Server, version 1709 (Server Core Installation)StatusaffectedConstraints-
- Version 3.5 on Windows Server, version 1803 (Server Core Installation)StatusaffectedConstraints-
- Version 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1StatusaffectedConstraints-
- Version 3.5.1 on Windows 7 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1StatusaffectedConstraints-
- Version 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)StatusaffectedConstraints-
- Version 4.5.2 on Windows 7 for 32-bit Systems Service Pack 1StatusaffectedConstraints-
- Version 4.5.2 on Windows 7 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 4.5.2 on Windows 8.1 for 32-bit systemsStatusaffectedConstraints-
- Version 4.5.2 on Windows 8.1 for x64-based systemsStatusaffectedConstraints-
- Version 4.5.2 on Windows RT 8.1StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2012StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2012 (Server Core installation)StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2012 R2StatusaffectedConstraints-
- Version 4.5.2 on Windows Server 2012 R2 (Server Core installation)StatusaffectedConstraints-
- Version 4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2StatusaffectedConstraints-
- Version 4.6 on Windows Server 2008 for x64-based Systems Service Pack 2StatusaffectedConstraints-
- Version 4.6.2/4.7/4.7.1 on Windows 10 Version 1607 for 32-bit SystemsStatusaffectedConstraints-
- Version 4.6.2/4.7/4.7.1 on Windows 10 Version 1607 for x64-based SystemsStatusaffectedConstraints-
- Version 4.6.2/4.7/4.7.1 on Windows Server 2016StatusaffectedConstraints-
- Version 4.6.2/4.7/4.7.1 on Windows Server 2016 (Server Core installation)StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit SystemsStatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2 on Windows 10 for x64-based SystemsStatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows 7 for 32-bit Systems Service Pack 1StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows 7 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows 8.1 for 32-bit systemsStatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows 8.1 for x64-based systemsStatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows RT 8.1StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2012StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2012 (Server Core installation)StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2012 R2StatusaffectedConstraints-
- Version 4.6/4.6.1/4.6.2/4.7/4.7.1 on Windows Server 2012 R2 (Server Core installation)StatusaffectedConstraints-
- Version 4.7.1 on Windows 10 Version 1709 for 32-bit SystemsStatusaffectedConstraints-
- Version 4.7.1 on Windows 10 Version 1709 for x64-based SystemsStatusaffectedConstraints-
- Version 4.7.1 on Windows Server, version 1709 (Server Core Installation)StatusaffectedConstraints-
- Version 4.7/4.7.1 on Windows 10 Version 1703 for 32-bit SystemsStatusaffectedConstraints-
- Version 4.7/4.7.1 on Windows 10 Version 1703 for x64-based SystemsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework | n/a |
|
Configuration 1
- 2.0
- 3.0
Running on/with
- n/a
Configuration 2
- 3.5
Running on/with
- n/a
- 1607
- 1703
- 1709
- 1803
- n/a
- n/a
- r2
- n/a
- 1709
- 1803
Configuration 3
- 3.5.1
Running on/with
- n/a
- r2
Configuration 4
- 4.5.2
Running on/with
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- r2
Configuration 5
- 4.6
Running on/with
- n/a
Configuration 6
- 4.6.2
- 4.7
- 4.7.1
Running on/with
- 1607
- n/a
Configuration 7
- 4.6
- 4.6.1
- 4.6.2
Running on/with
- n/a
Configuration 8
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
Running on/with
- n/a
- n/a
- n/a
- r2
- n/a
- r2
Configuration 9
- 4.7.1
Running on/with
- 1709
Configuration 10
- 4.7
- 4.7.1
Running on/with
- 1703
No data.
.NET Core 1.0 on Red Hat Enterprise Linux
rh-dotnetcore10-dotnetcore
Not affected
.NET Core 1.1 on Red Hat Enterprise Linux
rh-dotnetcore11-dotnetcore
Not affected
.NET Core 2.0 on Red Hat Enterprise Linux
rh-dotnet20-dotnet
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-dotnetcore | Not affected | n/a |
| .NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-dotnetcore | Not affected | n/a |
| .NET Core 2.0 on Red Hat Enterprise Linux | rh-dotnet20-dotnet | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The User Mode Code Integrity (UMCI) and Device Guard features are specific to certain versions of the Microsoft Windows operating system and not available with Red Hat Enterprise Linux.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.32% (0.01320) | 69.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.24% (0.01245) | 65.30th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.29% (0.00295) | 49.83th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.75% (0.01749) | 71.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.29% (0.00288) | 50.18th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00073) | 33.73th | v3 (v2023.03.01) |
| Mar 18, 2024 | 0.07% (0.00074) | 30.37th | v3 (v2023.03.01) |
| May 3, 2023 | 0.10% (0.00098) | 39.41th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00086) | 34.70th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.42% (0.01418) | 73.14th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.42% (0.01418) | 71.15th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.42% (0.01418) | 50.43th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.76% (0.08756) | 86.41th | v1 |
| Jan 6, 2022 | 8.76% (0.08756) | 86.25th | v1 |
| Sep 1, 2021 | 8.76% (0.08756) | 93.70th | v1 |
| Apr 14, 2021 | 8.76% (0.08756) | 0.00th | v1 |
References (7)
- http://www.securityfocus.com/bid/104072 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040851 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-1039 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1576633 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2018-1039
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1039 x_refsource_CONFIRMPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1039
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/104072 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1040851 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-1039 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1576633 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1039 | ||
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1039 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-1039 |
Change history (0)
No recorded changes yet.