SB2019021314 - Security restrictions bypass in Windows Defender Firewall 



SB2019021314 - Security restrictions bypass in Windows Defender Firewall

Published: February 13, 2019

Security Bulletin ID SB2019021314
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2019-0637)

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, when Windows is connected to both an ethernet and a cellular network. A remote attacker can bypass configured firewall policies and perform unauthorized actions against the affected system.

Note, this vulnerability cannot be triggered remotely.


Remediation

Install update from vendor's website.