CVE-2020-16891

EUVD-2020-8849
<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.</p>
<p>An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system.</p>
<p>The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.</p>
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
microsoftCNA
8.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_10
-
microsoftwindows_7
-
microsoftwindows_8.1
-
microsoftwindows_server_2008
-
microsoftwindows_server_2012
-
microsoftwindows_server_2016
-
microsoftwindows_server_2019
-
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
(x64)
1607 (x64)
1709 (x64)
1803 (x64)
1809 (x64)
1903 (x64)
1909 (x64)
2004 (x64)
Windows 7
Service Pack 1 (x64)
Windows 8.1
(x64)
Windows Server
1903 Server Core
1909 Server Core
2004 Server Core
Windows Server 2008
Service Pack 2 (x64)
Service Pack 2 Server Core (x64)
Windows Server 2008 R2
Service Pack 1 (x64)
Service Pack 1 Server Core (x64)
Windows Server 2012
Server Core
Standard
Windows Server 2012 R2
Server Core
Standard
Windows Server 2016
Server Core
Standard
Windows Server 2019
Server Core
Standard