CVE-2017-0181
published 2017-04-12CVE-2017-0181: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly…
PriorityP339high7.6CVSS 3.0
AVAACHPRHUINSCCHIHAH
EPSS
3.15%
86.5th percentile
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | windows_hyper-v | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
vendor_msrc7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Hyper-V Remote Code Execution Vulnerability
vendor_msrc·2017-04-11·CVSS 7.6
CVE-2017-0181 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.
The security update addresses the vulnerability by correcting how Windows Hyper-V Network Switch validates guest operating system network traffic.
Windows Hyper-V: Windows Hyper-V
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:N
GHSA
GHSA-xm6m-mhj5-wwv5: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an aut
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2017-0163 [HIGH] CWE-20 GHSA-xm6m-mhj5-wwv5: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an aut
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.
GHSA
GHSA-wffg-444q-6mw8: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2017-0162 [HIGH] CWE-20 GHSA-wffg-444q-6mw8: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0163, CVE-2017-0180, and CVE-2017-0181.
GHSA
GHSA-v4r4-q4jh-rhvg: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an aut
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2017-0180 [HIGH] CWE-20 GHSA-v4r4-q4jh-rhvg: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an aut
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181.
GHSA
GHSA-96j5-32rm-vphf: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to p
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2017-0181 [HIGH] CWE-20 GHSA-96j5-32rm-vphf: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to p
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.
No detection rules found.
No public exploits indexed.
Recorded Future
China's Influence on National Network Vulnerability Publications | Recorded Future
blogs_recorded_future·CVSS 7.8
[HIGH] China's Influence on National Network Vulnerability Publications | Recorded Future
## China’s Ministry of State Security Likely Influences National Network Vulnerability Publications
## Executive Summary
Earlier research based on the last two years of vulnerability reporting illustrated that China’s National Vulnerability Database of Information Security (CNNVD) was generally more aggressive in capturing up-to-date information for software vulnerabilities than its U.S. counterpart (NVD). In this research we examine exceptions to this general rule and discover a broader role for the Ministry of State Security (MSS) in vulnerability reporting than was previously known.
Recorded Future analysis has uncovered evidence of a formal vulnerability evaluation process at CNNVD in which High-threat CVEs are likely evaluated for their operational utility by the MSS before publica
Recorded Future
China's Influence on National Network Vulnerability Publications
blogs_recorded_future·CVSS 7.8
[HIGH] China's Influence on National Network Vulnerability Publications
# China’s Ministry of State Security Likely Influences National Network Vulnerability Publications
Click here to download the complete analysis as a PDF.
### Executive Summary
Earlier research based on the last two years of vulnerability reporting illustrated that China’s National Vulnerability Database of Information Security (CNNVD) was generally more aggressive in capturing up-to-date information for software vulnerabilities than its U.S. counterpart (NVD). In this research we examine exceptions to this general rule and discover a broader role for the Ministry of State Security (MSS) in vulnerability reporting than was previously known.
Recorded Future analysis has uncovered evidence of a formal vulnerability evaluation process at CNNVD in which High-threat CVEs are likely evaluated
http://www.securityfocus.com/bid/97445http://www.securitytracker.com/id/1038233https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0181http://www.securityfocus.com/bid/97445http://www.securitytracker.com/id/1038233https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0181
2017-04-12
Published