Windows Hyper-V Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to execute code on the Hyper-V host execution environment.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
🎯 Affected products14
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 for x64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server, version 20H2 (Server Core Installation)
✅ Remediation
KB5010351 (Security Update) — fixed build 10.0.17763.2565 KB5010345 (Security Update) — fixed build 10.0.18363.2094 KB5010342 (Security Update) — fixed build 10.0.19043.1526 KB5010354 (Security Update) — fixed build 10.0.20348.524 KB5010456 (Security Hotpatch Update) — fixed build 10.0.20348.525 KB5010342 (Security Update) — fixed build 10.0.19042.1526 KB5010386 (Security Update) — fixed build 10.0.22000.493 KB5010342 (Security Update) — fixed build 10.0.19044.1526 KB5010358 (Security Update) — fixed build 10.0.10240.19204 KB5010359 (Security Update) — fixed build 10.0.14393.4946
🔗 References (12)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21995
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010351
- referencehttps://support.microsoft.com/help/5010351
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010345
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010342
- referencehttps://support.microsoft.com/help/5010342
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010354
- referencehttps://support.microsoft.com/help/5010354
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010386
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010358
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010359
- referencehttps://support.microsoft.com/help/5010359