VYPR

Windows Hyper-V

by Microsoft

CVEs (84)

  • CVE-2017-0193HigJun 15, 2017
    risk 0.51cvss 7.8epss 0.01

    Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating…

  • CVE-2019-0709HigJun 12, 2019
    risk 0.50cvss 7.6epss 0.04

    A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating…

  • CVE-2019-0620HigJun 12, 2019
    risk 0.50cvss 7.6epss 0.01

    A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating…

  • CVE-2017-0212HigMay 12, 2017
    risk 0.49cvss 7.6epss 0.01

    Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability".

  • CVE-2026-32149HigApr 14, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2026-21247HigFeb 10, 2026
    risk 0.47cvss 7.3epss 0.01

    Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2026-25170HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54115HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50167HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27491HigApr 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.

  • CVE-2024-20659HigOct 8, 2024
    risk 0.46cvss 7.1epss 0.01

    Windows Hyper-V Security Feature Bypass Vulnerability

  • CVE-2025-49751MedAug 12, 2025
    risk 0.44cvss 6.8epss 0.00

    Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

  • CVE-2025-48807MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2025-47999MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.00

    Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

  • CVE-2022-44682MedDec 13, 2022
    risk 0.44cvss 6.8epss 0.01

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2021-42284MedNov 10, 2021
    risk 0.44cvss 6.8epss 0.03

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2020-0918MedApr 15, 2020
    risk 0.44cvss 6.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.

  • CVE-2020-0917MedApr 15, 2020
    risk 0.44cvss 6.8epss 0.02

    An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.

  • CVE-2019-0886MedMay 16, 2019
    risk 0.44cvss 6.8epss 0.02

    An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.

  • CVE-2024-30011MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.03

    Windows Hyper-V Denial of Service Vulnerability

VYPR — Vulnerability Intelligence