CVE-2021-26867CriticalCVSS 9.9
Windows Hyper-V Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Which Hyper-V systems are vulnerable? Any Hyper-V client which is configured to use the Plan 9 file system could be vulnerable. An authenticated attacker who successfully exploited this vulnerability on a Hyper-V client could cause code to execute on the Hyper-V server.
🎯 Affected products5
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows Server, version 2004 (Server Core installation)
- Windows Server, version 20H2 (Server Core Installation)
✅ Remediation
KB5000808 (Security Update) — fixed build 10.0.18363.1440 KB5000802 (Security Update) — fixed build 10.0.19043.867
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26867
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000808
- referencehttps://support.microsoft.com/help/5000808
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000802
- referencehttps://support.microsoft.com/help/5000802