CVE-2017-8706
published 2017-09-13CVE-2017-8706: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when…
PriorityP422medium5.3CVSS 3.0
AVLACHPRHUINSCCHINAN
EPSS
2.42%
82.3th percentile
The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | windows_hyper-v | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Hyper-V Information Disclosure Vulnerability
vendor_msrc·2017-09-12·CVSS 7.2
CVE-2017-8706 [MEDIUM] Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclose memory information.
An attacker who successfully exploited the vulnerability could gain access to information on the Hyper-V host operating system.
The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.
Windows Hyper-V: Windows Hyper-V
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Ex
GHSA
GHSA-pgrg-8fhr-7vx5: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8706 [MEDIUM] CWE-200 GHSA-pgrg-8fhr-7vx5: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili
The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-4j97-wvjp-h3gq: The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8707 [MEDIUM] CWE-200 GHSA-4j97-wvjp-h3gq: The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8
The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8706, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-h3g9-rw58-vgq2: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to pro
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8711 [MEDIUM] CWE-200 GHSA-h3g9-rw58-vgq2: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to pro
The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8706, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-6chf-jwrr-c4pv: The Windows Hyper-V component on Microsoft Windows Windows 8
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8713 [MEDIUM] CWE-200 GHSA-6chf-jwrr-c4pv: The Windows Hyper-V component on Microsoft Windows Windows 8
The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8706.
GHSA
GHSA-jpwm-6fvr-35jv: The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8712 [MEDIUM] CWE-200 GHSA-jpwm-6fvr-35jv: The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails
The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8706, and CVE-2017-8713.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100789http://www.securitytracker.com/id/1039317https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8706http://www.securityfocus.com/bid/100789http://www.securitytracker.com/id/1039317https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8706
2017-09-13
Published