CVE-2017-8746 describes a security feature bypass vulnerability in Windows Device Guard affecting Windows 10 versions 1607 and 1703, and Windows Server 2016. This flaw stems from how PowerShell handles functions and user-supplied code, allowing an attacker to bypass Device Guard protections. With a CVSS score of 5.3 (Medium), this vulnerability is locally exploitable with low attack complexity, potentially leading to limited impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was mentioned in a BleepingComputer article regarding Microsoft's September Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.