CVE-2017-0007
medium · 5.5Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."
5.5
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2017-03-17
Published
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10 | all versions |
| microsoft | windows_10 | 1511 |
| microsoft | windows_10 | 1607 |
| microsoft | windows_server_2016 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/96018
- http://www.securitytracker.com/id/1038001
- https://enigma0x3.net/2017/04/03/defeating-device-guard-a-look-into-cve-2017-0007/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0007
- http://www.securityfocus.com/bid/96018
- http://www.securitytracker.com/id/1038001
- https://enigma0x3.net/2017/04/03/defeating-device-guard-a-look-into-cve-2017-0007/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0007
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-0007