CVE-2020-1243: Windows Hyper-V Denial of Service Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Oct
Released
2020-10-13
EPSS Score
0.39% (percentile: 59.8%)

Description

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.

Affected Products (14)

Other

  • 11498
  • 11569
  • 11571
  • 11572
  • 11713
  • 11715
  • 11454
  • 11645
  • 11647
  • 11768
  • 11769
  • 10853
  • 10816
  • 10855

Security Updates (6)

Acknowledgments

Nicolas Economou from <a href="https://www.bluefrostsecurity.de/en/">Blue Frost Security</a>

Revision History

  • 2020-10-13: Information published.