High severity7.8NVD Advisory· Published Mar 14, 2018· Updated Jun 17, 2026
CVE-2018-0902
CVE-2018-0902
Description
The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver validates and enforces impersonation levels, aka "Windows Security Feature Bypass Vulnerability". This CVE is unique from CVE-2018-0884.
Affected products
10cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- Range: 2016, 1709
- Range: Gold, 1511, 1607, 1703, 1709
- Microsoft Corporation/Cryptography Next Generation (CNG) kernel-mode driver (cng.sys)v5Range: Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709
Patches
Vulnerability mechanics
References
3- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0902nvdPatchVendor Advisory
- www.securityfocus.com/bid/103266nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040520nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.