Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2017-8715 : What You Need to Know

Learn about CVE-2017-8715, a security vulnerability allowing bypass of Microsoft Device Guard on Windows 10 and Server 2016. Find mitigation steps and prevention measures here.

A security vulnerability known as "Windows Security Feature Bypass" allows circumvention of Microsoft Device Guard on various versions of Microsoft Windows 10 and Windows Server 2016.

Understanding CVE-2017-8715

This CVE involves a security feature bypass affecting Microsoft Device Guard on specific Windows versions.

What is CVE-2017-8715?

The vulnerability enables attackers to bypass the security features of Microsoft Device Guard by exploiting the handling of Windows PowerShell sessions on affected systems.

The Impact of CVE-2017-8715

The security flaw poses a risk of unauthorized access and potential compromise of systems protected by Microsoft Device Guard.

Technical Details of CVE-2017-8715

This section provides detailed technical information about the CVE.

Vulnerability Description

The vulnerability in Microsoft Device Guard allows for a security feature bypass due to the mishandling of Windows PowerShell sessions, known as "Windows Security Feature Bypass."

Affected Systems and Versions

        Product: Device Guard
        Vendor: Microsoft Corporation
        Affected Versions: Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016

Exploitation Mechanism

The vulnerability is exploited by manipulating Windows PowerShell sessions to bypass the security controls implemented by Microsoft Device Guard.

Mitigation and Prevention

Protecting systems from CVE-2017-8715 requires immediate actions and long-term security practices.

Immediate Steps to Take

        Apply security patches provided by Microsoft promptly.
        Implement least privilege access controls to limit potential attack surfaces.
        Monitor and restrict PowerShell usage to prevent unauthorized activities.

Long-Term Security Practices

        Regularly update and patch systems to address security vulnerabilities.
        Conduct security training for users to recognize and report suspicious activities.

Patching and Updates

Microsoft may release security updates and patches to address CVE-2017-8715. Stay informed about these releases and apply them as soon as possible.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now