High severity8.4NVD Advisory· Published Nov 12, 2019· Updated Jun 17, 2026
CVE-2019-1398
CVE-2019-1398
Description
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1397.
Affected products
12- Microsoft/Windows 10 Version 1903 for x64-based Systemsv5Range: unspecified
- Microsoft/Windows Server, version 1903 (Server Core installation)v5Range: unspecified
- Range: version 1803 (Core Installation)
cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:x64:*+ 3 more
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1398nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.