CVE-2021-38672CriticalCVSS 8.0

Windows Hyper-V Remote Code Execution Vulnerability

Published
October 12, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? For successful exploitation, this vulnerability could allow a malicious guest VM to read kernel memory in the host. To trigger this vulnerability the guest VM requires a memory allocation error to first occur on the guest VM. This bug could be used for a VM escape from guest to host.

🎯 Affected products3

  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KB5006699 (Security Update) — fixed build 10.0.20348.288 KB5006674 (Security Update) — fixed build 10.0.22000.258

🔗 References (3)