Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0109

 

Improper input validation in Microsoft Windows and Windows Server - CVE-2017-0109

Published: March 14, 2017


Vulnerability identifier: #VU6046
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0109
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker with access to guest operating system to compromise the host system.

The vulnerability exists due to improper input validation in Windows Hyper-V. An attacker with access to guest operating system can execute arbitrary code on the host operating system.

Successful exploitation of this vulnerability may allow an attacker to escalate privileges.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-0109

Install updates from vendor's website.



External References

Related Security Bulletins