SB20170314118 - Hyper-V Remote Code Execution Vulnerability
Published: March 14, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2017-0075)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker with access to guest operating system to compromise the host system.
Successful exploitation of this vulnerability may allow an attacker to escalate privileges.
Remediation
Install update from vendor's website.