PT-2017-1643 · Microsoft · Windows Server 2016+3

Jordan Rabet

+1

·

Published

2017-03-14

·

Updated

2019-10-03

·

CVE-2017-0021

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 1607 Windows Server 2016
Description The issue is related to improper validation of vSMB packet data in Hyper-V, allowing attackers to execute arbitrary code on a target OS. It is also described as a vulnerability related to insufficient access control in the Hyper-V application of the Windows operating system, which can be exploited by a specially crafted application. The vulnerability enables remote attackers to execute arbitrary code and affect the system.
Recommendations For Microsoft Windows 10 1607, update to a version that includes the fix for this issue. For Windows Server 2016, apply the necessary patch or update to resolve the vulnerability. As a temporary workaround, consider restricting access to Hyper-V to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00796
CVE-2017-0021

Affected Products

Hyper-V
Windows 10
Windows
Windows Server 2016