Access Restriction Bypass Affecting system.management.automation package, versions [6.1.0, 6.1.5) [6.2.0, 6.2.2)
Snyk CVSS
Attack Complexity
High
Threat Intelligence
EPSS
0.04% (9th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DOTNET-SYSTEMMANAGEMENTAUTOMATION-451667
- published 21 Jul 2019
- disclosed 19 Jul 2019
- credit Unknown
Introduced: 19 Jul 2019
CVE-2019-1167 Open this link in a new tabHow to fix?
Upgrade System.Management.Automation
to version 6.1.5, 6.2.2 or higher.
Overview
System.Management.Automation is a System Management Automation for PowerShell.
Affected versions of this package are vulnerable to Access Restriction Bypass. A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC
enforcement.