CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS13-092 | Vulnerability in Hyper-V Could Allow Elevation of Privilege (2893986) | Windows 8 | Important | 13-11-2013 |
Technical Information
Brief overview of the risk:
The vulnerability could allow elevation of privilege if an attacker passes a specially crafted function parameter in a hypercall from an existing running virtual machine to the hypervisor. The vulnerability could also allow denial of service for the Hyper-V host if the attacker passes a specially crafted function parameter in a hypercall from an existing running virtual machine to the hypervisor.
Detailed Information on the risk:
An elevation of privilege vulnerability exists in Hyper-V on Windows 8 and Windows Server 2012. An attacker who successfully exploited this vulnerability could execute arbitrary code as System in another virtual machine (VM) on the shared Hyper-V host. An attacker would not be able to execute code on the Hyper-V host, only on guest VMs on the same host. The vulnerability could also allow denial of service in Hyper-V on the same platforms, allowing an attacker to cause the Hyper-V host to stop responding or restart.
Further information on this exploit is available at : MS13-092
Affected Software
Windows 8 for x64-based SystemsWindows Server 2012