Medium severity5.3NVD Advisory· Published Aug 15, 2018· Updated Jun 17, 2026
CVE-2018-8200
CVE-2018-8200
Description
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8204.
Affected products
14- Range: version 1709 (Server Core Installation)
(Server Core installation)+ 4 more
- (no CPE)range: (Server Core installation)
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
- (no CPE)
32-bit Systems+ 5 more
- (no CPE)range: 32-bit Systems
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8200nvdPatchVendor Advisory
- www.securityfocus.com/bid/105007nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041459nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.