CVE-2020-0904: Windows Hyper-V Denial of Service Vulnerability
Overview
- Severity
- Medium (CVSS 6.5)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
- Category
- Denial of Service
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Sep
- Released
- 2020-09-08
- EPSS Score
- 0.66% (percentile: 71.0%)
Description
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.
Affected Products (27)
Other
- 11497
- 11498
- 11563
- 11568
- 11569
- 11570
- 11571
- 11572
- 11712
- 11713
- 11714
- 11715
- 11453
- 11454
- 11583
- 11644
- 11645
- 11646
- 11647
- 11766
- 11767
- 11768
- 11769
- 10852
- 10853
- 10816
- 10855
Security Updates (6)
Acknowledgments
<a href="https://twitter.com/ergot86">Daniel Fernandez Kuehr</a> of Blue Frost Security GmbH
Revision History
- 2020-09-08: Information published.