CVE Vulnerabilities

CVE-2018-0966

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Apr 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka Device Guard Security Feature Bypass Vulnerability. This affects Windows Server 2016, Windows 10, Windows 10 Servers.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
Windows_10Microsoft- (including)- (including)
Windows_10Microsoft1511 (including)1511 (including)
Windows_10Microsoft1607 (including)1607 (including)
Windows_10Microsoft1703 (including)1703 (including)
Windows_10Microsoft1709 (including)1709 (including)
Windows_server_2016Microsoft- (including)- (including)
Windows_server_2016Microsoft1709 (including)1709 (including)

Potential Mitigations

References