CVE-2019-0635Improper Input Validation in Microsoft Windows

Severity
6.2MEDIUMNVD
EPSS
0.5%
top 34.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 1.7 | Impact: 4.0

Affected Packages20 packages

CVEListV5microsoft/windows8 versions+7
NVDmicrosoft/windowsr2, 1709, 1803+2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-j2jm-rqw4-wfh2: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated2022-05-13

📋Vendor Advisories

1
Microsoft
Windows Hyper-V Information Disclosure Vulnerability2019-02-12
CVE-2019-0635 — Improper Input Validation in Microsoft | cvebase