Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2019-0710: Windows Hyper-V Denial of Service Vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Microsoft CVE-2019-0710: Windows Hyper-V Denial of Service Vulnerability

Severity
6
CVSS
(AV:A/AC:L/Au:S/C:N/I:N/A:C)
Published
06/11/2019
Created
06/12/2019
Added
06/11/2019
Modified
12/02/2022

Description

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The security update addresses the vulnerability by resolving a number of conditions where Hyper-V would fail to prevent a guest operating system from sending malicious requests.

Solution(s)

  • msft-kb4503267-1ed66fe1-79ac-4316-ab77-6f14315a2aaf
  • msft-kb4503267-9d442aa2-8250-4bce-a4cb-d5c0f0e940c3
  • msft-kb4503267-c5eebe52-ca4d-435a-9122-9e6143e4e7fa
  • msft-kb4503279-1204481c-d6d9-4c85-a4ce-3394d21dbb3a
  • msft-kb4503279-61eca38b-d713-45c7-83f9-a6f464c36d69
  • msft-kb4503284-294f4f95-b414-4c9f-b121-fb9eb6d57e4a
  • msft-kb4503284-a98b0e9f-7387-4ed3-a9eb-7e5edade968e
  • msft-kb4503286-40e9fcd2-99a5-4cb8-8219-492e2687796d
  • msft-kb4503286-dc868304-9b1c-482e-829c-8015cac2e793
  • msft-kb4503286-df22198b-20a3-4076-af48-0176479b97fa
  • msft-kb4503290-1a32764d-38ac-46c1-95fd-1bbb92147e05
  • msft-kb4503290-5b6fe378-dbd0-47a5-b088-1b2c530fdc58
  • msft-kb4503290-b489422c-7cde-4048-b72d-6ba8cfeb9ea5
  • msft-kb4503291-d189a6cc-fab4-4431-b68e-89bc0f472928
  • msft-kb4503291-e8b30f57-c262-4178-aad4-0e3fc1f4959f
  • msft-kb4503327-0268db13-0ba0-4fd0-9d07-e1c8985542d0
  • msft-kb4503327-664d546e-67b3-43f1-b1f9-4e240a41b6a5
  • msft-kb4503327-83c78a12-db5c-4f4d-ae53-c4db34e6f925

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;