Vulnerability & Exploit Database

Back to search

Microsoft CVE-2017-11899: Device Guard Security Feature Bypass Vulnerability

Severity CVSS Published Added Modified
7 (AV:N/AC:L/Au:N/C:P/I:P/A:P) December 12, 2017 December 12, 2017 September 07, 2018


A security feature bypass exists when Device Guard incorrectly validates an untrusted file. An attacker who successfully exploited this vulnerability could make an unsigned file appear to be signed. Because Device Guard relies on the signature to determine the file is non-malicious, Device Guard could then allow a malicious file to execute. In an attack scenario, an attacker could make an untrusted file appear to be a trusted file. The update addresses the vulnerability by correcting how Device Guard handles untrusted files.

Scan For This Vulnerability

Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities

 Free InsightVM Trial


Solution Reference

Microsoft Security Update Guide