CVE-2021-26867CriticalCVSS 9.9

Windows Hyper-V Remote Code Execution Vulnerability

Published
March 9, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Which Hyper-V systems are vulnerable? Any Hyper-V client which is configured to use the Plan 9 file system could be vulnerable. An authenticated attacker who successfully exploited this vulnerability on a Hyper-V client could cause code to execute on the Hyper-V server.

🎯 Affected products5

  • Windows 10 Version 1909 for x64-based Systems
  • Windows 10 Version 2004 for x64-based Systems
  • Windows Server, version 1909 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5000808 (Security Update) — fixed build 10.0.18363.1440 KB5000802 (Security Update) — fixed build 10.0.19043.867

🔗 References (5)