CVE-2017-8714
published 2017-09-13CVE-2017-8714: The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code…
PriorityP343high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
3.62%
88.2th percentile
The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Remote Desktop Virtual Host Remote Code Execution Vulnerability".
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | windows_hyper-v | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Remote Desktop Virtual Host Remote Code Execution Vulnerability
vendor_msrc·2017-09-12·CVSS 7.8
CVE-2017-8714 [HIGH] Remote Desktop Virtual Host Remote Code Execution Vulnerability
Remote Desktop Virtual Host Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the VM Host Agent Service of Remote Desktop Virtual Host role when it fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could issue a specially crafted certificate on the guest operating system that could cause the VM host agent service on the host operating system to execute arbitrary code. The Remote Desktop Virtual Host role is not enabled by default.
An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.
The security update addresses the vulnerability by correcting how VM host agent service validates guest operating system
GHSA
GHSA-24xv-qrr3-8vjf: The Windows Hyper-V component on Microsoft Windows 8
ghsa_unreviewed·2022-05-17
CVE-2017-8714 [HIGH] CWE-20 GHSA-24xv-qrr3-8vjf: The Windows Hyper-V component on Microsoft Windows 8
The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Remote Desktop Virtual Host Remote Code Execution Vulnerability".
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2017
blogs_talos·2017-09-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday - September 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 81 new vulnerabilities with 27 of them rated critical, 52 rated important, and 2 rated moderate. These vulnerabilities impact Edge, Hyper-V, Internet Explorer, Office, Remote Desktop Protocol, Sharepoint, Windows Graphic Display Interface, Windows Kernel Mode Drivers, and more. In addition, Microsoft is also releasing an update for Adobe Flash Player embedded in Edge and Internet Explorer.
Note that the Bluetooth vulnerabilities known as "BlueBorne" that affected Windows have been patched in this latest release. For more information, please refer to CVE-2017-8628.
## Vulnerabilities Rated CriticalThe followi
arXiv
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
arxiv_fulltext·2019-06-26
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
Orly Stan, Ron Bitton, Michal Ezrets, Moran Dadon, Yuval Elovici, Asaf Shabtai
Dept. of Software and Information Systems Engineering
Ben-Gurion University of the Negev
Masaki Inokuchi, Yoshinobu Ohta, Tomohiko Yagyu
Security Research Laboratories, NEC Corporation
O. Stan, et al.
## Abstract
Selecting the optimal set of countermeasures is a challenging task that involves various considerations and tradeoffs such as prioritizing the risks to mitigate and costs.
The vast majority of studies for selecting a countermeasure deployment are based on a limited risk assessment procedure that utilizes the common vulnerability scoring system (CVSS).
Such a risk assessment procedure does not necessarily consider the prerequi
http://www.securityfocus.com/bid/100797http://www.securitytracker.com/id/1039341https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8714http://www.securityfocus.com/bid/100797http://www.securitytracker.com/id/1039341https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8714
2017-09-13
Published