CVE-2018-0959
published 2018-05-09CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest…
PriorityP345high7.6CVSS 3.0
AVAACHPRHUINSCCHIHAH
EPSS
10.19%
95.1th percentile
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
vendor_msrc7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Hyper-V Remote Code Execution Vulnerability
vendor_msrc·2018-05-08·CVSS 7.6
CVE-2018-0959 [HIGH] Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.
The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.
Windows Hyper-V: Windows Hyper-V
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Rele
GHSA
GHSA-c9w2-52x6-j7c4: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu
ghsa_unreviewed·2022-05-14
CVE-2018-0959 [HIGH] CWE-20 GHSA-c9w2-52x6-j7c4: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
No detection rules found.
No public exploits indexed.
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that cou
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits y vulnerabilidades
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that co
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Ausnutzung von Schwachstellen
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
# Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro
2018/05/09
Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174, which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro 2018/05/09 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Qualys
May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
## OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174 , which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008, which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16.
### Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of these is notable and requires prompt attenti
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
## Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008 , which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16 .
## Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of thes
Qualys
May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
### OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174, which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
## Critical Vulnerabilities This month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed be
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
### Critical VulnerabilitiesThis month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed below:
CVE-2018-0870 - Internet Explorer Me
http://www.securityfocus.com/bid/104031http://www.securitytracker.com/id/1040843https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0959http://www.securityfocus.com/bid/104031http://www.securitytracker.com/id/1040843https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0959
2018-05-09
Published