SB2019021314 - Security restrictions bypass in Windows Defender Firewall
Published: February 13, 2019
Security Bulletin ID
SB2019021314
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2019-0637)
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, when Windows is connected to both an ethernet and a cellular network. A remote attacker can bypass configured firewall policies and perform unauthorized actions against the affected system.
Note, this vulnerability cannot be triggered remotely.
Remediation
Install update from vendor's website.