CVE-2019-0637 — Windows Defender Firewall Security Feature Bypass Vulnerability
Executive Summary
A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections. This vulnerability occurs when Windows is connected to both an ethernet network and a cellular network. An attacker would have no way to trigger this vulnerability remotely, and this vulnerability by itself does not allow Windows to be exploited. This update addresses the behavior by correcting how Windows Defender Firewall handles firewall profiles when ethernet and cellular network connections are both present.
Overview
CVSS Vector
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1709 for 32-bit Systems | 4486996 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1709 for ARM64-based Systems | 4486996 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1709 for x64-based Systems | 4486996 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1803 for 32-bit Systems | 4487017 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1803 for ARM64-based Systems | 4487017 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1803 for x64-based Systems | 4487017 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 4487044 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 4487044 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1809 for x64-based Systems | 4487044 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2019 | 4487044 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2019 (Server Core installation) | 4487044 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server, version 1709 (Server Core Installation) | 4486996 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server, version 1803 (Server Core Installation) | 4487017 (Security Update) |
Important | Security Feature Bypass | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4486996 |
Security Update | Yes |
4487017 |
Security Update | Yes |
4487044 |
Security Update | Yes |
Known Exploits
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.