CVE-2017-8625
Summary
| CVE | CVE-2017-8625 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-08 21:29:00 UTC |
| Updated | 2023-10-25 19:15:00 UTC |
| Description | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability". |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 11 | All | All | All |
| Application | Microsoft | Internet Explorer | 11 | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1511 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1511 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| UMCI vs Internet Explorer: Exploring CVE-2017–8625 – Posts By SpecterOps Team Members | MISC | posts.specterops.io | Exploit, Third Party Advisory |
| Bypassing Device guard UMCI using CHM – CVE-2017-8625 – Oddvar Moe's Blog | MISC | oddvar.moe | |
| Microsoft Internet Explorer CVE-2017-8625 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft Internet Explorer Policy Validation Flaw Lets Local Users Bypass User Mode Code Integrity Policy - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8625 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Bypassing Device guard UMCI using CHM – CVE-2017-8625 – MSitPros Blog | MISC | msitpros.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.