CVE-2017-11830
MEDIUM
5,3
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
MEDIUM
4,6
Source: [email protected]
Access Vector: local
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial
Description
AI Translation Available
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka 'Device Guard Security Feature Bypass Vulnerability'.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0531
Percentile
0,9th
Updated
EPSS Score Trend (Last 90 Days)
367
Time-of-check Time-of-use (TOCTOU) Race Condition
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Other
Non-Repudiation
Potential Impacts:
Alter Execution Logic
Unexpected State
Modify Application Data
Modify Files Or Directories
Modify Memory
Other
Hide Activities
Applicable Platforms
All platforms may be affected
Exploit
Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature …
VerifiedMicrosoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
View Exploit Code →
Operating System
Windows Server 2016 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server:1709:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-118…
https://www.exploit-db.com/exploits/43162/
http://www.securityfocus.com/bid/101714
http://www.securitytracker.com/id/1039790
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-118…
https://www.exploit-db.com/exploits/43162/
http://www.securityfocus.com/bid/101714
http://www.securitytracker.com/id/1039790