PT-2019-1830 · Microsoft · Windows Hyper-V+2

Published

2019-04-09

·

Updated

2020-08-24

·

CVE-2019-0786

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Server Message Block (SMB) Server (affected versions not specified) Windows Hyper-V (affected versions not specified)
Description The issue is related to an elevation of privilege vulnerability in the Microsoft Server Message Block (SMB) Server. It occurs when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine. Additionally, there is a vulnerability in the Windows operating system related to insufficient validation of packet data in the Windows Hyper-V component. This vulnerability can be exploited by an attacker to execute arbitrary code using a specially crafted application. The vulnerability allows remote attackers to execute arbitrary code and affect the system.
Recommendations For Microsoft Server Message Block (SMB) Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Windows Hyper-V, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01482
CVE-2019-0786

Affected Products

Server Message Block (Smb) Server
Windows
Windows Hyper-V