CVE-2019-0886Improper Input Validation in Microsoft Windows

Severity
6.8MEDIUMNVD
EPSS
1.1%
top 22.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 24

Description

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 2.3 | Impact: 4.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-67wv-vphq-h3gr: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated2022-05-24

📋Vendor Advisories

1
Microsoft
Windows Hyper-V Information Disclosure Vulnerability2019-05-14
CVE-2019-0886 — Improper Input Validation in Microsoft | cvebase