96698vdb entry
http://www.securityfocus.com/bid/96698 CVE-2017-0075
HIGH
Record summary
CVE-2017-0075 has a selected CVSS score of 7.6 (high); EIP currently links 2 repository PoCs.
Description
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0109.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 | affected |
Proofs of concept
2Repository PoCs
GitHub4B5F5F4B/HyperVRepository PoCby 4B5F5F4BStars: 34Not analyzed18 files
GitHubbelyakovvitagmailt/4B5F5F4BpRepository PoCby belyakovvitagmailtStars: 0Not analyzed1 file
References
41037999vdb entry
http://www.securitytracker.com/id/1037999 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0075 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0075