Red Hat Bugzilla – Bug 1576633
CVE-2018-1039 dotnet: Device Guard security bypass can allow for privilege escalation
Last modified: 2018-05-13 21:08:37 EDT
A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard. An attacker who successfully exploited this vulnerability could circumvent a User Mode Code Integrity (UMCI) policy on the machine. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. External References: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1039