VYPR
Medium severity5.3NVD Advisory· Published Jun 14, 2018· Updated Jun 17, 2026

CVE-2018-8217

CVE-2018-8217

Description

A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8221.

Affected products

8
  • Microsoft/Windows Server 2016llm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
    • (no CPE)range: (Server Core installation)
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
    • (no CPE)range: 32-bit Systems

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.