Search

Find a vulnerability

Search criteria

    16 vulnerabilities found for PowerShell Core by Microsoft

    CVE-2019-1167 (GCVE-0-2019-1167)

    Vulnerability from nvd – Published: 2019-07-19 14:34 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.690Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka \u0027Windows Defender Application Control Security Feature Bypass Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-19T14:34:19.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1167",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka \u0027Windows Defender Application Control Security Feature Bypass Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1167",
        "datePublished": "2019-07-19T14:34:19.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.690Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0657 (GCVE-0-2019-0657)

    Vulnerability from nvd – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Spoofing
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2019:0349 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/106890 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Microsoft Microsoft .NET Framework 4.5.2 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows RT 8.1
    Affected: Windows Server 2012 R2 (Server Core installation)
    Affected: Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6 Affected: Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft .NET Core Affected: 1
    Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Microsoft Microsoft Visual Studio Affected: 2017
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7.2 Affected: Windows 10 Version 1803 for 32-bit Systems
    Affected: Windows 10 Version 1803 for x64-based Systems
    Affected: Windows Server, version 1803 (Server Core Installation)
    Affected: Windows 10 Version 1803 for ARM64-based Systems
    Affected: Windows 10 Version 1809 for 32-bit Systems
    Affected: Windows 10 Version 1809 for x64-based Systems
    Affected: Windows Server 2019
    Affected: Windows Server 2019 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6/4.6.1/4.6.2 Affected: Windows 10 for 32-bit Systems
    Affected: Windows 10 for x64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows RT 8.1
    Affected: Windows Server 2012 R2 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Affected: Windows Server 2016
    Affected: Windows 10 Version 1607 for 32-bit Systems
    Affected: Windows 10 Version 1607 for x64-based Systems
    Affected: Windows Server 2016 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7/4.7.1/4.7.2 Affected: Windows 10 Version 1703 for 32-bit Systems
    Affected: Windows 10 Version 1703 for x64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7.1/4.7.2 Affected: Windows 10 Version 1709 for 32-bit Systems
    Affected: Windows 10 Version 1709 for x64-based Systems
    Affected: Windows Server, version 1709 (Server Core Installation)
    Affected: Windows 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Microsoft Microsoft Visual Studio 2017 Affected: version 15.9
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.5 Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows Server 2012 R2 (Server Core installation)
    Affected: Windows 10 for 32-bit Systems
    Affected: Windows 10 for x64-based Systems
    Affected: Windows Server 2016
    Affected: Windows 10 Version 1607 for 32-bit Systems
    Affected: Windows 10 Version 1607 for x64-based Systems
    Affected: Windows 10 Version 1703 for 32-bit Systems
    Affected: Windows 10 Version 1703 for x64-based Systems
    Affected: Windows 10 Version 1709 for 32-bit Systems
    Affected: Windows 10 Version 1709 for x64-based Systems
    Affected: Windows Server, version 1709 (Server Core Installation)
    Affected: Windows 10 Version 1803 for 32-bit Systems
    Affected: Windows 10 Version 1803 for x64-based Systems
    Affected: Windows Server, version 1803 (Server Core Installation)
    Affected: Windows 10 Version 1803 for ARM64-based Systems
    Affected: Windows 10 Version 1809 for 32-bit Systems
    Affected: Windows 10 Version 1809 for x64-based Systems
    Affected: Windows Server 2019
    Affected: Windows Server 2019 (Server Core installation)
    Affected: Windows 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.0 Affected: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Affected: Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 2.0 Affected: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.5.1 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.244Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2019:0349",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0349"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
              },
              {
                "name": "106890",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106890"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Microsoft .NET Framework 4.5.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            },
            {
              "product": "Microsoft Visual Studio",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2017"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019  (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6/4.6.1/4.6.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for x64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2016  (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for x64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            },
            {
              "product": "Microsoft Visual Studio 2017",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 15.9"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.5",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.0",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 2.0",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.5.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability exists in certain .Net Framework API\u0027s and Visual Studio in the way they parse URL\u0027s, aka \u0027.NET Framework and Visual Studio Spoofing Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Spoofing",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "RHSA-2019:0349",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0349"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
            },
            {
              "name": "106890",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106890"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0657",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Microsoft .NET Framework 4.5.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows RT 8.1"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1"
                              },
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft Visual Studio",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2017"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2019"
                              },
                              {
                                "version_value": "Windows Server 2019  (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6/4.6.1/4.6.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 for x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows RT 8.1"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2016"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2016  (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft Visual Studio 2017",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 15.9"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.5",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2016"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2019"
                              },
                              {
                                "version_value": "Windows Server 2019  (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.0",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              },
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 2.0",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.5.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability exists in certain .Net Framework API\u0027s and Visual Studio in the way they parse URL\u0027s, aka \u0027.NET Framework and Visual Studio Spoofing Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Spoofing"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2019:0349",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0349"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
                },
                {
                  "name": "106890",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106890"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0657",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0632 (GCVE-0-2019-0632)

    Vulnerability from nvd – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.708Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
              },
              {
                "name": "106880",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106880"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
            },
            {
              "name": "106880",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106880"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0632",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
                },
                {
                  "name": "106880",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106880"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0632",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0631 (GCVE-0-2019-0631)

    Vulnerability from nvd – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.917Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "106875",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106875"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "106875",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106875"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0631",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "106875",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106875"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0631",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.917Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0627 (GCVE-0-2019-0627)

    Vulnerability from nvd – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.865Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
              },
              {
                "name": "106857",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106857"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
            },
            {
              "name": "106857",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106857"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0627",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
                },
                {
                  "name": "106857",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106857"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0627",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.865Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8415 (GCVE-0-2018-8415)

    Vulnerability from nvd – Published: 2018-11-14 01:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
    Severity
    No CVSS data available.
    CWE
    • Tampering
    References
    URL Tags
    http://www.securitytracker.com/id/1042108 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/105792 vdb-entryx_refsource_BID
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft Windows 7 Affected: 32-bit Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Create a notification for this product.
    Microsoft Windows Server 2012 R2 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows RT 8.1 Affected: Windows RT 8.1
    Create a notification for this product.
    Microsoft Windows Server 2012 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2019 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 8.1 Affected: 32-bit systems
    Affected: x64-based systems
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.0
    Affected: 6.1
    Create a notification for this product.
    Microsoft Windows Server 2016 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2008 R2 Affected: x64-based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1 (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 10 Affected: 32-bit Systems
    Affected: Version 1607 for 32-bit Systems
    Affected: Version 1607 for x64-based Systems
    Affected: Version 1703 for 32-bit Systems
    Affected: Version 1703 for x64-based Systems
    Affected: Version 1709 for 32-bit Systems
    Affected: Version 1709 for ARM64-based Systems
    Affected: Version 1709 for x64-based Systems
    Affected: Version 1803 for 32-bit Systems
    Affected: Version 1803 for ARM64-based Systems
    Affected: Version 1803 for x64-based Systems
    Affected: Version 1809 for 32-bit Systems
    Affected: Version 1809 for ARM64-based Systems
    Affected: Version 1809 for x64-based Systems
    Affected: x64-based Systems
    Create a notification for this product.
    Microsoft Windows 10 Servers Affected: version 1709 (Server Core Installation)
    Affected: version 1803 (Server Core Installation)
    Create a notification for this product.
    Date Public
    2018-11-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.516Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1042108",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1042108"
              },
              {
                "name": "105792",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105792"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows 7",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                }
              ]
            },
            {
              "product": "Windows Server 2012 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows RT 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                }
              ]
            },
            {
              "product": "Windows Server 2012",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based systems"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                }
              ]
            },
            {
              "product": "Windows Server 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2008 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 10",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems"
                }
              ]
            },
            {
              "product": "Windows 10 Servers",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Server Core Installation)"
                }
              ]
            }
          ],
          "datePublic": "2018-11-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka \"Microsoft PowerShell Tampering Vulnerability.\" This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Tampering",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-14T10:57:02.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1042108",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1042108"
            },
            {
              "name": "105792",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105792"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8415",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows 7",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows RT 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows RT 8.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2019",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit systems"
                              },
                              {
                                "version_value": "x64-based systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              },
                              {
                                "version_value": "6.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2016",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2008 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1709 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10 Servers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka \"Microsoft PowerShell Tampering Vulnerability.\" This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Tampering"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1042108",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1042108"
                },
                {
                  "name": "105792",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105792"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8415",
        "datePublished": "2018-11-14T01:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.516Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8256 (GCVE-0-2018-8256)

    Vulnerability from nvd – Published: 2018-11-14 01:00 – Updated: 2024-08-05 06:46
    VLAI
    Summary
    A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1.
    Severity
    No CVSS data available.
    CWE
    • Remote Code Execution
    References
    URL Tags
    http://www.securitytracker.com/id/1042108 vdb-entryx_refsource_SECTRACK
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/105781 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Microsoft Windows 7 Affected: 32-bit Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Create a notification for this product.
    Microsoft Microsoft.PowerShell.Archive Affected: 1.2.2.0
    Create a notification for this product.
    Microsoft Windows 10 Servers Affected: version 1709 (Server Core Installation)
    Affected: version 1803 (Server Core Installation)
    Create a notification for this product.
    Microsoft Windows Server 2012 R2 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows RT 8.1 Affected: Windows RT 8.1
    Create a notification for this product.
    Microsoft Windows Server 2008 R2 Affected: Itanium-Based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1 (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2012 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.0
    Affected: 6.1
    Create a notification for this product.
    Microsoft Windows Server 2016 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 8.1 Affected: 32-bit systems
    Affected: x64-based systems
    Create a notification for this product.
    Microsoft Windows 10 Affected: 32-bit Systems
    Affected: Version 1607 for 32-bit Systems
    Affected: Version 1607 for x64-based Systems
    Affected: Version 1703 for 32-bit Systems
    Affected: Version 1703 for x64-based Systems
    Affected: Version 1709 for 32-bit Systems
    Affected: Version 1709 for ARM64-based Systems
    Affected: Version 1709 for x64-based Systems
    Affected: Version 1803 for 32-bit Systems
    Affected: Version 1803 for ARM64-based Systems
    Affected: Version 1803 for x64-based Systems
    Affected: Version 1809 for 32-bit Systems
    Affected: Version 1809 for ARM64-based Systems
    Affected: Version 1809 for x64-based Systems
    Affected: x64-based Systems
    Create a notification for this product.
    Microsoft Windows Server 2019 Affected: (Server Core installation)
    Create a notification for this product.
    Date Public
    2018-11-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:46:13.720Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1042108",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1042108"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
              },
              {
                "name": "105781",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105781"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows 7",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                }
              ]
            },
            {
              "product": "Microsoft.PowerShell.Archive",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.2.0"
                }
              ]
            },
            {
              "product": "Windows 10 Servers",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Server Core Installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2012 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows RT 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                }
              ]
            },
            {
              "product": "Windows Server 2008 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2012",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                }
              ]
            },
            {
              "product": "Windows Server 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based systems"
                }
              ]
            },
            {
              "product": "Windows 10",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            }
          ],
          "datePublic": "2018-11-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka \"Microsoft PowerShell Remote Code Execution Vulnerability.\" This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-14T10:57:02.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1042108",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1042108"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
            },
            {
              "name": "105781",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105781"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8256",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows 7",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft.PowerShell.Archive",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.2.2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10 Servers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows RT 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows RT 8.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2008 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              },
                              {
                                "version_value": "6.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2016",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit systems"
                              },
                              {
                                "version_value": "x64-based systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1709 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2019",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka \"Microsoft PowerShell Remote Code Execution Vulnerability.\" This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1042108",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1042108"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
                },
                {
                  "name": "105781",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105781"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8256",
        "datePublished": "2018-11-14T01:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:46:13.720Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8292 (GCVE-0-2018-8292)

    Vulnerability from nvd – Published: 2018-10-10 13:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
    Severity
    No CVSS data available.
    CWE
    • Information Disclosure
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2018:2902 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/105548 vdb-entryx_refsource_BID
    Impacted products
    Date Public
    2018-10-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.373Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2018:2902",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:2902"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
              },
              {
                "name": "105548",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105548"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2018-10-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "RHSA-2018:2902",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:2902"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
            },
            {
              "name": "105548",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105548"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8292",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information Disclosure"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2018:2902",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:2902"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
                },
                {
                  "name": "105548",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105548"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8292",
        "datePublished": "2018-10-10T13:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.373Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-1167 (GCVE-0-2019-1167)

    Vulnerability from cvelistv5 – Published: 2019-07-19 14:34 – Updated: 2024-08-04 18:06
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T18:06:31.690Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka \u0027Windows Defender Application Control Security Feature Bypass Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-19T14:34:19.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-1167",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka \u0027Windows Defender Application Control Security Feature Bypass Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167",
                  "refsource": "MISC",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-1167",
        "datePublished": "2019-07-19T14:34:19.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T18:06:31.690Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0632 (GCVE-0-2019-0632)

    Vulnerability from cvelistv5 – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.708Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
              },
              {
                "name": "106880",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106880"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
            },
            {
              "name": "106880",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106880"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0632",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0632"
                },
                {
                  "name": "106880",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106880"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0632",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0657 (GCVE-0-2019-0657)

    Vulnerability from cvelistv5 – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
    Severity
    No CVSS data available.
    CWE
    • Spoofing
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2019:0349 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/106890 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Microsoft Microsoft .NET Framework 4.5.2 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows RT 8.1
    Affected: Windows Server 2012 R2 (Server Core installation)
    Affected: Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6 Affected: Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft .NET Core Affected: 1
    Affected: 2.1
    Affected: 2.2
    Create a notification for this product.
    Microsoft Microsoft Visual Studio Affected: 2017
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7.2 Affected: Windows 10 Version 1803 for 32-bit Systems
    Affected: Windows 10 Version 1803 for x64-based Systems
    Affected: Windows Server, version 1803 (Server Core Installation)
    Affected: Windows 10 Version 1803 for ARM64-based Systems
    Affected: Windows 10 Version 1809 for 32-bit Systems
    Affected: Windows 10 Version 1809 for x64-based Systems
    Affected: Windows Server 2019
    Affected: Windows Server 2019 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6/4.6.1/4.6.2 Affected: Windows 10 for 32-bit Systems
    Affected: Windows 10 for x64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows RT 8.1
    Affected: Windows Server 2012 R2 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Affected: Windows Server 2016
    Affected: Windows 10 Version 1607 for 32-bit Systems
    Affected: Windows 10 Version 1607 for x64-based Systems
    Affected: Windows Server 2016 (Server Core installation)
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7/4.7.1/4.7.2 Affected: Windows 10 Version 1703 for 32-bit Systems
    Affected: Windows 10 Version 1703 for x64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 4.7.1/4.7.2 Affected: Windows 10 Version 1709 for 32-bit Systems
    Affected: Windows 10 Version 1709 for x64-based Systems
    Affected: Windows Server, version 1709 (Server Core Installation)
    Affected: Windows 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Microsoft Microsoft Visual Studio 2017 Affected: version 15.9
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.5 Affected: Windows Server 2012
    Affected: Windows Server 2012 (Server Core installation)
    Affected: Windows 8.1 for 32-bit systems
    Affected: Windows 8.1 for x64-based systems
    Affected: Windows Server 2012 R2
    Affected: Windows Server 2012 R2 (Server Core installation)
    Affected: Windows 10 for 32-bit Systems
    Affected: Windows 10 for x64-based Systems
    Affected: Windows Server 2016
    Affected: Windows 10 Version 1607 for 32-bit Systems
    Affected: Windows 10 Version 1607 for x64-based Systems
    Affected: Windows 10 Version 1703 for 32-bit Systems
    Affected: Windows 10 Version 1703 for x64-based Systems
    Affected: Windows 10 Version 1709 for 32-bit Systems
    Affected: Windows 10 Version 1709 for x64-based Systems
    Affected: Windows Server, version 1709 (Server Core Installation)
    Affected: Windows 10 Version 1803 for 32-bit Systems
    Affected: Windows 10 Version 1803 for x64-based Systems
    Affected: Windows Server, version 1803 (Server Core Installation)
    Affected: Windows 10 Version 1803 for ARM64-based Systems
    Affected: Windows 10 Version 1809 for 32-bit Systems
    Affected: Windows 10 Version 1809 for x64-based Systems
    Affected: Windows Server 2019
    Affected: Windows Server 2019 (Server Core installation)
    Affected: Windows 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.0 Affected: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Affected: Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
    Affected: Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 2.0 Affected: Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
    Create a notification for this product.
    Microsoft Microsoft .NET Framework 3.5.1 Affected: Windows 7 for 32-bit Systems Service Pack 1
    Affected: Windows 7 for x64-based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
    Affected: Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
    Affected: Windows Server 2008 R2 for x64-based Systems Service Pack 1
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:27.244Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2019:0349",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:0349"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
              },
              {
                "name": "106890",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106890"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Microsoft .NET Framework 4.5.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                }
              ]
            },
            {
              "product": "Microsoft Visual Studio",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2017"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019  (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6/4.6.1/4.6.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for x64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2016  (Server Core installation)"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7/4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for x64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 4.7.1/4.7.2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            },
            {
              "product": "Microsoft Visual Studio 2017",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 15.9"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.5",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows Server 2012"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for 32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 8.1 for x64-based systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2012 R2 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2016"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server, version 1803  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2019  (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows 10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.0",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                },
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 2.0",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                }
              ]
            },
            {
              "product": "Microsoft .NET Framework 3.5.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows 7 for 32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows 7 for x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability exists in certain .Net Framework API\u0027s and Visual Studio in the way they parse URL\u0027s, aka \u0027.NET Framework and Visual Studio Spoofing Vulnerability\u0027."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Spoofing",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "RHSA-2019:0349",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:0349"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
            },
            {
              "name": "106890",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106890"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0657",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Microsoft .NET Framework 4.5.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows RT 8.1"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1"
                              },
                              {
                                "version_value": "2.1"
                              },
                              {
                                "version_value": "2.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft Visual Studio",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2017"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2019"
                              },
                              {
                                "version_value": "Windows Server 2019  (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6/4.6.1/4.6.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 for x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows RT 8.1"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2016"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2016  (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7/4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 4.7.1/4.7.2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft Visual Studio 2017",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 15.9"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.5",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows Server 2012"
                              },
                              {
                                "version_value": "Windows Server 2012 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 8.1 for 32-bit systems"
                              },
                              {
                                "version_value": "Windows 8.1 for x64-based systems"
                              },
                              {
                                "version_value": "Windows Server 2012 R2"
                              },
                              {
                                "version_value": "Windows Server 2012 R2 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 10 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2016"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server, version 1803  (Server Core Installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Windows 10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "Windows Server 2019"
                              },
                              {
                                "version_value": "Windows Server 2019  (Server Core installation)"
                              },
                              {
                                "version_value": "Windows 10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.0",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              },
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2"
                              },
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 2.0",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft .NET Framework 3.5.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows 7 for 32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows 7 for x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "Windows Server 2008 R2 for x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability exists in certain .Net Framework API\u0027s and Visual Studio in the way they parse URL\u0027s, aka \u0027.NET Framework and Visual Studio Spoofing Vulnerability\u0027."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Spoofing"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2019:0349",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:0349"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0657"
                },
                {
                  "name": "106890",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106890"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0657",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:27.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0627 (GCVE-0-2019-0627)

    Vulnerability from cvelistv5 – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.865Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
              },
              {
                "name": "106857",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106857"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
            },
            {
              "name": "106857",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106857"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0627",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0627"
                },
                {
                  "name": "106857",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106857"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0627",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.865Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-0631 (GCVE-0-2019-0631)

    Vulnerability from cvelistv5 – Published: 2019-03-06 00:00 – Updated: 2024-08-04 17:51
    VLAI
    Summary
    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632.
    Severity
    No CVSS data available.
    CWE
    • Security Feature Bypass
    References
    Impacted products
    Vendor Product Version
    Microsoft Windows Affected: 10 for 32-bit Systems
    Affected: 10 for x64-based Systems
    Affected: 10 Version 1607 for 32-bit Systems
    Affected: 10 Version 1607 for x64-based Systems
    Affected: 10 Version 1703 for 32-bit Systems
    Affected: 10 Version 1703 for x64-based Systems
    Affected: 10 Version 1709 for 32-bit Systems
    Affected: 10 Version 1709 for x64-based Systems
    Affected: 10 Version 1803 for 32-bit Systems
    Affected: 10 Version 1803 for x64-based Systems
    Affected: 10 Version 1803 for ARM64-based Systems
    Affected: 10 Version 1809 for 32-bit Systems
    Affected: 10 Version 1809 for x64-based Systems
    Affected: 10 Version 1809 for ARM64-based Systems
    Affected: 10 Version 1709 for ARM64-based Systems
    Create a notification for this product.
    Microsoft Windows Server Affected: 2016
    Affected: 2016 (Core installation)
    Affected: version 1709 (Core Installation)
    Affected: version 1803 (Core Installation)
    Affected: 2019
    Affected: 2019 (Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.1
    Affected: 6.2
    Create a notification for this product.
    Date Public
    2019-03-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:51:26.917Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "106875",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106875"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "10 Version 1709 for ARM64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "2016"
                },
                {
                  "status": "affected",
                  "version": "2016  (Core installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1709  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "2019"
                },
                {
                  "status": "affected",
                  "version": "2019  (Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "datePublic": "2019-03-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Feature Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-06T10:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "106875",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106875"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2019-0631",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "10 Version 1709 for ARM64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "2016"
                              },
                              {
                                "version_value": "2016  (Core installation)"
                              },
                              {
                                "version_value": "version 1709  (Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Core Installation)"
                              },
                              {
                                "version_value": "2019"
                              },
                              {
                                "version_value": "2019  (Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.1"
                              },
                              {
                                "version_value": "6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka \u0027Windows Security Feature Bypass Vulnerability\u0027. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Security Feature Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "106875",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106875"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0631"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2019-0631",
        "datePublished": "2019-03-06T00:00:00.000Z",
        "dateReserved": "2018-11-26T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:51:26.917Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8256 (GCVE-0-2018-8256)

    Vulnerability from cvelistv5 – Published: 2018-11-14 01:00 – Updated: 2024-08-05 06:46
    VLAI
    Summary
    A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1.
    Severity
    No CVSS data available.
    CWE
    • Remote Code Execution
    References
    URL Tags
    http://www.securitytracker.com/id/1042108 vdb-entryx_refsource_SECTRACK
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/105781 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Microsoft Windows 7 Affected: 32-bit Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Create a notification for this product.
    Microsoft Microsoft.PowerShell.Archive Affected: 1.2.2.0
    Create a notification for this product.
    Microsoft Windows 10 Servers Affected: version 1709 (Server Core Installation)
    Affected: version 1803 (Server Core Installation)
    Create a notification for this product.
    Microsoft Windows Server 2012 R2 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows RT 8.1 Affected: Windows RT 8.1
    Create a notification for this product.
    Microsoft Windows Server 2008 R2 Affected: Itanium-Based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1 (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2012 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.0
    Affected: 6.1
    Create a notification for this product.
    Microsoft Windows Server 2016 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 8.1 Affected: 32-bit systems
    Affected: x64-based systems
    Create a notification for this product.
    Microsoft Windows 10 Affected: 32-bit Systems
    Affected: Version 1607 for 32-bit Systems
    Affected: Version 1607 for x64-based Systems
    Affected: Version 1703 for 32-bit Systems
    Affected: Version 1703 for x64-based Systems
    Affected: Version 1709 for 32-bit Systems
    Affected: Version 1709 for ARM64-based Systems
    Affected: Version 1709 for x64-based Systems
    Affected: Version 1803 for 32-bit Systems
    Affected: Version 1803 for ARM64-based Systems
    Affected: Version 1803 for x64-based Systems
    Affected: Version 1809 for 32-bit Systems
    Affected: Version 1809 for ARM64-based Systems
    Affected: Version 1809 for x64-based Systems
    Affected: x64-based Systems
    Create a notification for this product.
    Microsoft Windows Server 2019 Affected: (Server Core installation)
    Create a notification for this product.
    Date Public
    2018-11-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:46:13.720Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1042108",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1042108"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
              },
              {
                "name": "105781",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105781"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows 7",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                }
              ]
            },
            {
              "product": "Microsoft.PowerShell.Archive",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.2.2.0"
                }
              ]
            },
            {
              "product": "Windows 10 Servers",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Server Core Installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2012 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows RT 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                }
              ]
            },
            {
              "product": "Windows Server 2008 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Itanium-Based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2012",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                }
              ]
            },
            {
              "product": "Windows Server 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based systems"
                }
              ]
            },
            {
              "product": "Windows 10",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems"
                }
              ]
            },
            {
              "product": "Windows Server 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            }
          ],
          "datePublic": "2018-11-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka \"Microsoft PowerShell Remote Code Execution Vulnerability.\" This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-14T10:57:02.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1042108",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1042108"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
            },
            {
              "name": "105781",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105781"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8256",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows 7",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Microsoft.PowerShell.Archive",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.2.2.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10 Servers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows RT 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows RT 8.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2008 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Itanium-Based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              },
                              {
                                "version_value": "6.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2016",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit systems"
                              },
                              {
                                "version_value": "x64-based systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1709 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2019",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka \"Microsoft PowerShell Remote Code Execution Vulnerability.\" This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1042108",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1042108"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8256"
                },
                {
                  "name": "105781",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105781"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8256",
        "datePublished": "2018-11-14T01:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:46:13.720Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8415 (GCVE-0-2018-8415)

    Vulnerability from cvelistv5 – Published: 2018-11-14 01:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
    Severity
    No CVSS data available.
    CWE
    • Tampering
    References
    URL Tags
    http://www.securitytracker.com/id/1042108 vdb-entryx_refsource_SECTRACK
    http://www.securityfocus.com/bid/105792 vdb-entryx_refsource_BID
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Microsoft Windows 7 Affected: 32-bit Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1
    Create a notification for this product.
    Microsoft Windows Server 2012 R2 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows RT 8.1 Affected: Windows RT 8.1
    Create a notification for this product.
    Microsoft Windows Server 2012 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2019 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 8.1 Affected: 32-bit systems
    Affected: x64-based systems
    Create a notification for this product.
    Microsoft PowerShell Core Affected: 6.0
    Affected: 6.1
    Create a notification for this product.
    Microsoft Windows Server 2016 Affected: (Server Core installation)
    Create a notification for this product.
    Microsoft Windows Server 2008 R2 Affected: x64-based Systems Service Pack 1
    Affected: x64-based Systems Service Pack 1 (Server Core installation)
    Create a notification for this product.
    Microsoft Windows 10 Affected: 32-bit Systems
    Affected: Version 1607 for 32-bit Systems
    Affected: Version 1607 for x64-based Systems
    Affected: Version 1703 for 32-bit Systems
    Affected: Version 1703 for x64-based Systems
    Affected: Version 1709 for 32-bit Systems
    Affected: Version 1709 for ARM64-based Systems
    Affected: Version 1709 for x64-based Systems
    Affected: Version 1803 for 32-bit Systems
    Affected: Version 1803 for ARM64-based Systems
    Affected: Version 1803 for x64-based Systems
    Affected: Version 1809 for 32-bit Systems
    Affected: Version 1809 for ARM64-based Systems
    Affected: Version 1809 for x64-based Systems
    Affected: x64-based Systems
    Create a notification for this product.
    Microsoft Windows 10 Servers Affected: version 1709 (Server Core Installation)
    Affected: version 1803 (Server Core Installation)
    Create a notification for this product.
    Date Public
    2018-11-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.516Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "1042108",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1042108"
              },
              {
                "name": "105792",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105792"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Windows 7",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                }
              ]
            },
            {
              "product": "Windows Server 2012 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows RT 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "Windows RT 8.1"
                }
              ]
            },
            {
              "product": "Windows Server 2012",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 8.1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based systems"
                }
              ]
            },
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                }
              ]
            },
            {
              "product": "Windows Server 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "(Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows Server 2008 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems Service Pack 1 (Server Core installation)"
                }
              ]
            },
            {
              "product": "Windows 10",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1607 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1703 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1709 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1803 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for 32-bit Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for ARM64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "Version 1809 for x64-based Systems"
                },
                {
                  "status": "affected",
                  "version": "x64-based Systems"
                }
              ]
            },
            {
              "product": "Windows 10 Servers",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "version 1709  (Server Core Installation)"
                },
                {
                  "status": "affected",
                  "version": "version 1803  (Server Core Installation)"
                }
              ]
            }
          ],
          "datePublic": "2018-11-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka \"Microsoft PowerShell Tampering Vulnerability.\" This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Tampering",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-11-14T10:57:02.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "1042108",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1042108"
            },
            {
              "name": "105792",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105792"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8415",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Windows 7",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows RT 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Windows RT 8.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2012",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2019",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 8.1",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit systems"
                              },
                              {
                                "version_value": "x64-based systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              },
                              {
                                "version_value": "6.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2016",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "(Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows Server 2008 R2",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "x64-based Systems Service Pack 1"
                              },
                              {
                                "version_value": "x64-based Systems Service Pack 1 (Server Core installation)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1607 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1703 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1703 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1709 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1709 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1803 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1803 for x64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for 32-bit Systems"
                              },
                              {
                                "version_value": "Version 1809 for ARM64-based Systems"
                              },
                              {
                                "version_value": "Version 1809 for x64-based Systems"
                              },
                              {
                                "version_value": "x64-based Systems"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Windows 10 Servers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "version 1709  (Server Core Installation)"
                              },
                              {
                                "version_value": "version 1803  (Server Core Installation)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka \"Microsoft PowerShell Tampering Vulnerability.\" This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Tampering"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "1042108",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1042108"
                },
                {
                  "name": "105792",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105792"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8415"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8415",
        "datePublished": "2018-11-14T01:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.516Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-8292 (GCVE-0-2018-8292)

    Vulnerability from cvelistv5 – Published: 2018-10-10 13:00 – Updated: 2024-08-05 06:54
    VLAI
    Summary
    An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
    Severity
    No CVSS data available.
    CWE
    • Information Disclosure
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2018:2902 vendor-advisoryx_refsource_REDHAT
    https://portal.msrc.microsoft.com/en-US/security-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/105548 vdb-entryx_refsource_BID
    Impacted products
    Date Public
    2018-10-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T06:54:36.373Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2018:2902",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:2902"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
              },
              {
                "name": "105548",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/105548"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "PowerShell Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                }
              ]
            },
            {
              "product": ".NET Core",
              "vendor": "Microsoft",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                },
                {
                  "status": "affected",
                  "version": "1.1"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                }
              ]
            }
          ],
          "datePublic": "2018-10-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T09:57:01.000Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "RHSA-2018:2902",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:2902"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
            },
            {
              "name": "105548",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/105548"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secure@microsoft.com",
              "ID": "CVE-2018-8292",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "PowerShell Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "6.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": ".NET Core",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.0"
                              },
                              {
                                "version_value": "1.1"
                              },
                              {
                                "version_value": "2.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Microsoft"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka \".NET Core Information Disclosure Vulnerability.\" This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information Disclosure"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2018:2902",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:2902"
                },
                {
                  "name": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292",
                  "refsource": "CONFIRM",
                  "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292"
                },
                {
                  "name": "105548",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/105548"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2018-8292",
        "datePublished": "2018-10-10T13:00:00.000Z",
        "dateReserved": "2018-03-14T00:00:00.000Z",
        "dateUpdated": "2024-08-05T06:54:36.373Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }