CVE-2019-1398Improper Input Validation in Microsoft Windows

Severity
8.4HIGHNVD
EPSS
0.7%
top 26.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1397.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.7 | Impact: 6.0

Affected Packages5 packages

CVEListV5microsoft/windows_server13 versions+12
CVEListV5microsoft/windows7 versions+6
NVDmicrosoft/windowsr2, 1803, 1903+2
NVDmicrosoft/windows_105 versions+4

Patches

🔴Vulnerability Details

6
GHSA
GHSA-f4wh-c3m6-3xxv: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu2022-05-24
GHSA
GHSA-hwxc-7rw6-2gqf: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu2022-05-24
GHSA
GHSA-mccc-vqrp-w855: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu2022-05-24
CVEList
CVE-2019-1398: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu2019-11-12
CVEList
CVE-2019-1397: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a gu2019-11-12

📋Vendor Advisories

1
Microsoft
Windows Hyper-V Remote Code Execution Vulnerability2019-11-12

🕵️Threat Intelligence

7
Trendmicro
November Patch Tuesday: 74 Fixes Before Major Update2019-11-13
Trendmicro
November Patch Tuesday: 74 Fixes Before Major Update2019-11-13
Qualys
November 2019 Patch Tuesday – 74 vulns, 13 Critical, Actively Attacked IE vuln, Hyper-V escapes, Adobe2019-11-12
Talos
Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage2019-11-12
Talos
Microsoft Patch Tuesday — Nov. 2019: Vulnerability disclosures and Snort coverage2019-11-12
CVE-2019-1398 — Improper Input Validation in Microsoft | cvebase