Back

HIGH

dotnet: Device Guard security bypass can allow for privilege escalation

Published May 9, 2018

Description

A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.

Affected products

Remediation

Red Hat statement

The User Mode Code Integrity (UMCI) and Device Guard features are specific to certain versions of the Microsoft Windows operating system and not available with Red Hat Enterprise Linux.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published May 9, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 8, 2018