Microsoft Windows Hyper-V Multiple Vulnerabilties
Last Update Date:
13 Apr 2016 12:03
Release Date:
13 Apr 2016
3719
Views
RISK: High Risk
TYPE: Operating Systems - Windows OS
- Hyper-V Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code. Customers who have not enabled the Hyper-V role are not affected. - Multiple Hyper-V Information Disclosure Vulnerabilities
Information disclosure vulnerabilities exist when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerabilities, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclose memory information. Customers who have not enabled the Hyper-V role are not affected.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 and Windows Server 2012 R2
- Microsoft Windows 10
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS16-045
Vulnerability Identifier
Source
Related Link
Share with