[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CNG Security Feature Bypass Vulnerability - CVE-2018-0902

ID: oval:org.secpod.oval:def:44629Date: (C)2018-03-15   (M)2024-03-06
Class: VULNERABILITYFamily: windows




A security feature bypass vulnerability exists in the Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) when it fails to properly validate and enforce impersonation levels. An attacker could exploit this vulnerability by convincing a user to run a specially crafted application that is designed to cause CNG to improperly validate impersonation levels, potentially allowing the attacker to gain access to information beyond the access level of the local user. The security update addresses the vulnerability by correcting how the kernel-mode driver validates and enforces impersonation levels.

Platform:
Microsoft Windows 10
Microsoft Windows Server 2016
Reference:
CVE-2018-0902
CVE    1
CVE-2018-0902
CPE    16
cpe:/o:microsoft:windows_10
cpe:/o:microsoft:windows_10:1511
cpe:/o:microsoft:windows_server_2016:::x64
cpe:/o:microsoft:windows_10:1607:::x64
...

© SecPod Technologies