Out-of-bounds memory access in Microsoft Windows and Windows Server - CVE-2017-0074

 

Out-of-bounds memory access in Microsoft Windows and Windows Server - CVE-2017-0074

Published: March 14, 2017


Vulnerability identifier: #VU6037
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0074
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker with privileged access to guest operating system to perform a denial of service (DoS) attack.

The vulnerability exists due to out-of-bounds memory access in Microsoft Hyper-V Network Switch. An attacker with privileged access to guest operating system can use a specially crafted application to trigger out-of-bounds memory access and cause the host machine to crash.

Successful exploitation of this vulnerability may result denial of service attack again the host system.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-0074

Install updates from vendor's website.



External References

Related Security Bulletins