CVE-2019-0710
Description
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The security update addresses the vulnerability by resolving a number of conditions where Hyper-V would fail to prevent a guest operating system from sending malicious requests.
Affected products
27- Microsoft/Windows 10 Version 1803v5Range: 10.0.0
- Microsoft/Windows Server, version 1803 (Server Core Installation)v5Range: 10.0.0
- Range: 10.0.0
- Microsoft/Windows Server 2016 (Server Core installation)v5Range: 10.0.14393.0
- Microsoft/Windows Server 2012 R2 (Server Core installation)v5Range: 6.3.9600.0
- Microsoft/Windows Server 2019 (Server Core installation)v5Range: 10.0.17763.0
- Range: 10.0.0
10.0.17763.0+ 1 more
- (no CPE)range: 10.0.17763.0
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
- Range: 10.0.0
10.0.10240.0+ 6 more
- (no CPE)range: 10.0.10240.0
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:*
- Range: 10.0.14393.0
10.0.14393.0+ 2 more
- (no CPE)range: 10.0.14393.0
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
6.3.0+ 1 more
- (no CPE)range: 6.3.0
- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x64:*
6.3.9600.0+ 1 more
- (no CPE)range: 6.3.9600.0
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.