CNG Security Feature Bypass Vulnerability - CVE-2018-0902ID: oval:org.secpod.oval:def:44629 | Date: (C)2018-03-15 (M)2024-03-06 |
Class: VULNERABILITY | Family: windows |
A security feature bypass vulnerability exists in the Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) when it fails to properly validate and enforce impersonation levels. An attacker could exploit this vulnerability by convincing a user to run a specially crafted application that is designed to cause CNG to improperly validate impersonation levels, potentially allowing the attacker to gain access to information beyond the access level of the local user. The security update addresses the vulnerability by correcting how the kernel-mode driver validates and enforces impersonation levels.
Platform: |
Microsoft Windows 10 |
Microsoft Windows Server 2016 |