CVE-2022-24466
published 2022-05-10CVE-2022-24466: Windows Hyper-V Security Feature Bypass Vulnerability
PriorityP419medium4.1CVSS 3.1
AVAACLPRLUINSCCNILAN
EPSS
0.70%
49.0th percentile
Windows Hyper-V Security Feature Bypass Vulnerability
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1706 | 10.0.19044.1706 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.675 | 10.0.22000.675 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.707 | 10.0.20348.707 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
nvdv2.02.3LOWAV:A/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Hyper-V Security Feature Bypass Vulnerability
vendor_msrc·2022-05-10·CVSS 4.1
CVE-2022-24466 [MEDIUM] Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This Hyper-V vulnerability relates to a Virtual Machine Switch with virtual networking in Hyper-V Network Virtualization (HNV). It might be possible to bypass extended ACLs and other Windows security feature checks.
See Create Security Policies with Extended Port Access Control Lists for information about extended ACLs.
FAQ: According to the CVSS metric, the Hyper-V attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Where the attack vector metric is Adjacent (A), this represents virtual machines connected via a Hyper-V Network Virtualization (HNV) logical network. This configuration forms an isolation boundary
GHSA
GHSA-hpw9-5gqc-mg62: Windows Hyper-V Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-11
CVE-2022-24466 [MEDIUM] CWE-863 GHSA-hpw9-5gqc-mg62: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-10
Published