CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
CVE-2024-49117 | Windows Hyper-V Remote Code Execution Vulnerability | Windows 11 | Critical | 02-01-2025 |
Technical Information
An authenticated attacker having low privileges may send specially crafted file operation requests on the guest VM to hardware resources and gain remote code execution on the host server. After successfull exploitation, the attacker could impact beyond the initially targeted VM by executing cross-VM attack and compromising multiple virtual machines on the server.
Patch release date: Dec 10, 2024
Further information on this vulnerability is available at : CVE-2024-49117
Affected Software
Windows Server 2022,Windows Server 2022 (Server Core installation),
Windows 11 Version 22H2 for ARM64-based Systems,
Windows 11 Version 22H2 for x64-based Systems,
Windows Server 2025 (Server Core installation),
Windows 11 Version 23H2 for ARM64-based Systems,
Windows 11 Version 23H2 for x64-based Systems,
Windows Server 2022, 23H2 Edition (Server Core installation),
Windows 11 Version 24H2 for ARM64-based Systems,
Windows 11 Version 24H2 for x64-based Systems,
Windows Server 2025