CVE-2019-0632 is a security feature bypass vulnerability in Windows that specifically allows an attacker to bypass Device Guard, affecting Microsoft Windows 10, Windows Server 2016, and Windows Server 2019, as well as PowerShell Core. This vulnerability carries a high CVSS score of 7.8, indicating that a local attacker with low privileges can achieve high impact on confidentiality, integrity, and availability without user interaction. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has received minimal community discussion and media coverage, with one article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:6.1:*:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:a:microsoft:powershell_core:6.2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.