SB2019021317 - Security restrictions bypass in Windows Device Guard
Published: February 13, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-0627)
The vulnerability allows a local user to bypass certain security restrictions.The vulnerability exists due to an error in Device Guard that can circumvent a User Mode Code Integrity (UMCI) policy on the machine. A local user can create a specially crafted program, bypass the User Mode Code Integrity policy and executed malicious application on the system.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-0632)
The vulnerability allows a local user to bypass certain security restrictions.The vulnerability exists due to an error in Device Guard that can circumvent a User Mode Code Integrity (UMCI) policy on the machine. A local user can create a specially crafted program, bypass the User Mode Code Integrity policy and executed malicious application on the system.
3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-0631)
The vulnerability allows a local user to bypass certain security restrictions.The vulnerability exists due to an error in Device Guard that can circumvent a User Mode Code Integrity (UMCI) policy on the machine. A local user can create a specially crafted program, bypass the User Mode Code Integrity policy and executed malicious application on the system.
Remediation
Install update from vendor's website.