CVE-2020-17095CriticalCVSS 8.5
Windows Hyper-V Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker could run a specially crafted application on a Hyper-V guest that could cause the Hyper-V host operating system to execute arbitrary code when it fails to properly validate vSMB packet data.
🎯 Affected products14
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1903 (Server Core installation)
- Windows Server, version 1909 (Server Core installation)
- Windows Server, version 2004 (Server Core installation)
- Windows Server, version 20H2 (Server Core Installation)
✅ Remediation
KB4592438 (Security Update) KB4592446 (Security Update) KB4592440 (Security Update) KB4592449 (Security Update) KB4593226 (Security Update)
🔗 References (11)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17095
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592438
- referencehttps://support.microsoft.com/help/4592438
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592446
- referencehttps://support.microsoft.com/help/4592446
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592440
- referencehttps://support.microsoft.com/help/4592440
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592449
- referencehttps://support.microsoft.com/help/4592449
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4593226
- referencehttps://support.microsoft.com/help/4593226