CVE-2020-16894: Windows NAT Denial of Service Vulnerability

Overview

Severity
High (CVSS 7.7)
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Oct
Released
2020-10-13
Last Updated
2020-10-16
EPSS Score
1.14% (percentile: 78.5%)

Description

A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. The update addresses the vulnerability by modifying how Windows NAT accesses the host.

Affected Products (3)

Other

  • 10853
  • 10816
  • 10855

Security Updates (1)

Acknowledgments

Huichen Lin and Dong Seong Kim of <a href="https://www.itee.uq.edu.au/">School of Information Technology and Electrical Engineering - The University of Queensland</a>

Revision History

  • 2020-10-13: Information published.
  • 2020-10-16: Corrected the CVE description and title. This is an informational change only.