CVE-2009-1542

Microsoft Virtual PC and Virtual Server - Privilege Escalation via VMM Instruction Decoding

Title source: llm
STIX 2.1

Description

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1890
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35808
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022544
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-195A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6166

Scores

EPSS 0.0798
EPSS Percentile 94.2%

Details

CWE
CWE-264
Status published
Products (3)
microsoft/virtual_pc 2004 sp1
microsoft/virtual_pc 2007 (3 CPE variants)
microsoft/virtual_server 2005 r2_sp1 (2 CPE variants)
Published Jul 15, 2009
Tracked Since Feb 18, 2026