VYPR

Windows Defender Application Control

by Microsoft

CVEs (6)

  • CVE-2025-26678HigApr 8, 2025
    risk 0.55cvss 8.4epss 0.01

    Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-59033HigSep 8, 2025
    risk 0.48cvss 7.4epss 0.00

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash…

  • CVE-2024-43645MedNov 12, 2024
    risk 0.44cvss 6.7epss 0.01

    Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

  • CVE-2020-0951MedSep 11, 2020
    risk 0.44cvss 6.7epss 0.07

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by…

  • CVE-2022-21906MedJan 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Windows Defender Application Control Security Feature Bypass Vulnerability

  • CVE-2019-0733MedMay 16, 2019
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.