Improper input validation in Windows and Windows Server - CVE-2017-0109

 

Improper input validation in Windows and Windows Server - CVE-2017-0109

Published: March 14, 2017


Vulnerability identifier: #VU6046
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-0109
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server

Detailed vulnerability description

The vulnerability allows a remote attacker with access to guest operating system to compromise the host system.

The vulnerability exists due to improper input validation in Windows Hyper-V. An attacker with access to guest operating system can execute arbitrary code on the host operating system.

Successful exploitation of this vulnerability may allow an attacker to escalate privileges.


How to mitigate CVE-2017-0109

Install updates from vendor's website.


Sources