CVE-2020-0904: Windows Hyper-V Denial of Service Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Sep
Released
2020-09-08
EPSS Score
0.66% (percentile: 71.0%)

Description

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.

Affected Products (27)

Other

  • 11497
  • 11498
  • 11563
  • 11568
  • 11569
  • 11570
  • 11571
  • 11572
  • 11712
  • 11713
  • 11714
  • 11715
  • 11453
  • 11454
  • 11583
  • 11644
  • 11645
  • 11646
  • 11647
  • 11766
  • 11767
  • 11768
  • 11769
  • 10852
  • 10853
  • 10816
  • 10855

Security Updates (6)

Acknowledgments

<a href="https://twitter.com/ergot86">Daniel Fernandez Kuehr</a> of Blue Frost Security GmbH

Revision History

  • 2020-09-08: Information published.