Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0075

 

Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0075

Published: March 14, 2017


Vulnerability identifier: #VU6044
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0075
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker with access to guest operating system to compromise the host system.

The vulnerability exists due to improper input validation in Windows Hyper-V. An attacker with access to guest operating system can execute arbitrary code on the host operating system.

Successful exploitation of this vulnerability may allow an attacker to escalate privileges.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-0075

Install updates from vendor's website.



External References

Related Security Bulletins