cbcvebase.
CVE-2021-28476
published 2021-05-11

CVE-2021-28476: Windows Hyper-V Remote Code Execution Vulnerability

PriorityP275critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
38.63%
98.4th percentile
Windows Hyper-V Remote Code Execution Vulnerability

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1893110.0.10240.18931
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.440110.0.14393.4401
microsoftwindows_10_version_1803>= 10.0.0 < 10.0.17134.220710.0.17134.2207
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.193510.0.17763.1935
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.155610.0.18363.1556
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.98210.0.19041.982
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.245976.1.7601.24597
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.245986.1.7601.24598
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.200176.3.9600.20017
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.245976.1.7601.24597
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.245986.1.7601.24598
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.245976.1.7601.24597
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.245986.1.7601.24598
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.211176.0.6003.21117
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.233476.2.9200.23347
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.200176.3.9600.20017
microsoftwindows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

  • A guest VM can force the Hyper-V host's kernel to read from an arbitrary, potentially invalid address — monitor for unexpected Hyper-V host bugchecks (kernel crashes) originating from guest VM activity as a sign of exploitation attempts.
  • Exploitation may trigger hardware device-specific side effects via memory-mapped device registers — monitor for anomalous hardware device behaviour on Hyper-V hosts that correlates with guest VM network activity.
  • ·The vulnerability affects the Windows Hyper-V role specifically; exploitation requires the attacker to control a guest VM on the target Hyper-V host.
  • ·Microsoft assessed exploitation as 'Less Likely' for both latest and older software releases at time of disclosure, and confirmed no known in-the-wild exploitation.

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.