logo

CVE-2018–8212: Device Guard/CLM bypass using MSFT_ScriptResource

ID: 037a7476-e9db-5e70-953f-7ca9d5d4a77e

STIX ID: report--037a7476-e9db-5e70-953f-7ca9d5d4a77e

Feed Name: SpecterOps Blog

Threat Score
60/100

Date Published: 2018-10-10

Date Updated: 2026-04-30

Author: Matt Nelson

...
...

This report demonstrates a Constrained Language Mode (CLM) bypass for Device Guard by abusing the Microsoft-signed PowerShell module MSFT_ScriptResource.psm1: its exported Get-TargetResource function creates and invokes a ScriptBlock from the -GetScript parameter, enabling execution of unsigned code in FullLanguage mode; the issue was addressed in CVE-2018-8212.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.