CVE-2017-8664Improper Input Validation in Corporation Windows Hyper-v

Severity
8.8HIGHNVD
EPSS
0.9%
top 23.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 17

Description

Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages11 packages

CVEListV5microsoft_corporation/windows_hyper-vWindows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016

Patches

🔴Vulnerability Details

1
GHSA
GHSA-rcq4-7j6p-3gmc: Windows Hyper-V in Windows 82022-05-17

📋Vendor Advisories

1
Microsoft
Windows Hyper-V Remote Code Execution Vulnerability2017-08-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - August 20172017-08-08
Talos
Microsoft Patch Tuesday - August 20172017-08-08