CVE-2017-8625

Scores

EPSS

0.698medium69.8%
0%20%40%60%80%100%

Percentile: 69.8%

CVSS

8.8high3.x
0246810

CVSS Score: 8.8/10

All CVSS Scores

CVSS 3.x
8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka “Internet Explorer Security Feature Bypass Vulnerability”.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

msrcnvd

CWEs

CWE-276

Exploits

Exploit ID: CVE-2017-8625

Source: github-poc

URL: https://github.com/homjxi0e/CVE-2017-8625_Bypass_UMCI

Vulnerable Software (4)

Type: Configuration

Vendor: *

Product: internet_explorer

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 14393.1593

Operating System: Windows 14393 build 1593

Identifier: KB4034658

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10586.1045

Operating System: Windows 10586 build 1045

Identifier: KB4034660

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10240.17533

Operating System: Windows 10240 build 17533

Identifier: KB4034668

Source: msrc

End of list