CVE-2020-0890: Windows Hyper-V Denial of Service Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Sep
Released
2020-09-08
EPSS Score
11.15% (percentile: 93.5%)

Description

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.

Detection & Weaponization (1 sources)

Maturity: Exploit

  • GitHub PoC: 3 repositories

Affected Products (20)

Other

  • 11497
  • 11498
  • 11563
  • 11568
  • 11569
  • 11570
  • 11571
  • 11572
  • 11712
  • 11713
  • 11714
  • 11715
  • 11644
  • 11645
  • 11646
  • 11647
  • 11766
  • 11767
  • 11768
  • 11769

Security Updates (4)

Acknowledgments

<a href="https://twitter.com/ergot86">Daniel Fernandez Kuehr</a> of Blue Frost Security GmbH, <a href=https://twitter.com/gerhart_x>Arthur Khudyaev</a>

Revision History

  • 2020-09-08: Information published.