Rewterz
Rewterz Threat Advisory – Wireshark Dissection Engine Denial of Service Vulnerability
May 23, 2019
Rewterz
Rewterz Threat Alert – Shade Ransomware Hits High-Tech, Wholesale & Education Sectors in Multiple Countries
May 24, 2019

Rewterz Threat Advisory – Microsoft PowerShell Core Multiple Vulnerabilities

Severity

Medium

Analysis Summary

Multiple vulnerabilities have been reported in Microsoft PowerShell Core, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to cause a DoS (Denial of Service).

CVE-2019-0981
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests.

CVE-2019-0980
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. This vulnerability is different from CVE-2019-0981.

CVE-2019-0733
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka ‘Windows Defender Application Control Security Feature Bypass Vulnerability’.

Impact

  • Denial of Service
  • Security Bypass

Affected Vendors

Microsoft

Affected Products

  • Microsoft PowerShell Core 6.1.x prior to 6.1.4
  • Microsoft PowerShell Core 6.2.x prior to 6.2.1.

Remediation

Update to version 6.1.4 or 6.2.1.