<< Back
CVE Number Vulnerability Product Severity Date
CVE-2024-49117 Windows Hyper-V Remote Code Execution Vulnerability Windows 11 Critical 02-01-2025

Technical Information

An authenticated attacker having low privileges may send specially crafted file operation requests on the guest VM to hardware resources and gain remote code execution on the host server. After successfull exploitation, the attacker could impact beyond the initially targeted VM by executing cross-VM attack and compromising multiple virtual machines on the server.

Patch release date: Dec 10, 2024
Further information on this vulnerability is available at : CVE-2024-49117

Affected Software

Windows Server 2022,
Windows Server 2022 (Server Core installation),
Windows 11 Version 22H2 for ARM64-based Systems,
Windows 11 Version 22H2 for x64-based Systems,
Windows Server 2025 (Server Core installation),
Windows 11 Version 23H2 for ARM64-based Systems,
Windows 11 Version 23H2 for x64-based Systems,
Windows Server 2022, 23H2 Edition (Server Core installation),
Windows 11 Version 24H2 for ARM64-based Systems,
Windows 11 Version 24H2 for x64-based Systems,
Windows Server 2025