8.8
CVE-2020-16891
- EPSS 0.55%
- Veröffentlicht 16.10.2020 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:07:20
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.</p> <p>An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.</p> <p>The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.</p>
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version- HwPlatformx64
Microsoft ≫ Windows 10 Version1607 HwPlatformx64
Microsoft ≫ Windows 10 Version1709 HwPlatformx64
Microsoft ≫ Windows 10 Version1803 HwPlatformx64
Microsoft ≫ Windows 10 Version1809 HwPlatformx64
Microsoft ≫ Windows 10 Version1903 HwPlatformx64
Microsoft ≫ Windows 10 Version1909 HwPlatformx64
Microsoft ≫ Windows 10 Version2004 HwPlatformx64
Microsoft ≫ Windows 8.1 Version- SwEdition- HwPlatformx64
Microsoft ≫ Windows Server 2008 Version- Updatesp2 SwEdition- HwPlatformx64
Microsoft ≫ Windows Server 2008 Versionr2 Updatesp1 HwPlatformx64
Microsoft ≫ Windows Server 2012 Version-
Microsoft ≫ Windows Server 2012 Versionr2 SwEdition- HwPlatform-
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2016 Version1903
Microsoft ≫ Windows Server 2016 Version1909
Microsoft ≫ Windows Server 2016 Version2004
Microsoft ≫ Windows Server 2019 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.55% | 0.67 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
secure@microsoft.com | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.