CVE-2020-0617Improper Input Validation in Microsoft Windows

Severity
6.0MEDIUMNVD
EPSS
0.4%
top 38.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 24

Description

A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 1.5 | Impact: 4.0

Affected Packages4 packages

CVEListV5microsoft/windows_server5 versions+4
CVEListV5microsoft/windows5 versions+4
NVDmicrosoft/windows_104 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4qqm-9p8q-xcfc: A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user o2022-05-24
CVEList
CVE-2020-0617: A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user o2020-01-14

📋Vendor Advisories

1
Microsoft
Hyper-V Denial of Service Vulnerability2020-01-14

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage2020-01-14
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage2020-01-14
CVE-2020-0617 — Improper Input Validation in Microsoft | cvebase