Severity
Medium
Analysis Summary
Multiple vulnerabilities have been reported in Microsoft PowerShell Core, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to cause a DoS (Denial of Service).
CVE-2019-0981
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests.
CVE-2019-0980
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests. This vulnerability is different from CVE-2019-0981.
CVE-2019-0733
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka ‘Windows Defender Application Control Security Feature Bypass Vulnerability’.
Impact
Affected Vendors
Microsoft
Affected Products
Remediation
Update to version 6.1.4 or 6.2.1.