<< Back
CVE Number Vulnerability Product Severity Date
MS13-092 Vulnerability in Hyper-V Could Allow Elevation of Privilege (2893986) Windows 8 Important 13-11-2013

Technical Information

Brief overview of the risk:
The vulnerability could allow elevation of privilege if an attacker passes a specially crafted function parameter in a hypercall from an existing running virtual machine to the hypervisor. The vulnerability could also allow denial of service for the Hyper-V host if the attacker passes a specially crafted function parameter in a hypercall from an existing running virtual machine to the hypervisor.
Detailed Information on the risk:

An elevation of privilege vulnerability exists in Hyper-V on Windows 8 and Windows Server 2012. An attacker who successfully exploited this vulnerability could execute arbitrary code as System in another virtual machine (VM) on the shared Hyper-V host. An attacker would not be able to execute code on the Hyper-V host, only on guest VMs on the same host. The vulnerability could also allow denial of service in Hyper-V on the same platforms, allowing an attacker to cause the Hyper-V host to stop responding or restart.


Further information on this exploit is available at : MS13-092

Affected Software

Windows 8 for x64-based Systems
Windows Server 2012