HIGH
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers
Published May 9, 2018
7.6
HIGHCVSS 3.0
EPSS 3.16%
Description
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Affected products
-
- Version Version 1607 for x64-based SystemsStatusaffectedConstraints-
- Version Version 1703 for x64-based SystemsStatusaffectedConstraints-
- Version Version 1709 for x64-based SystemsStatusaffectedConstraints-
- Version Version 1803 for x64-based SystemsStatusaffectedConstraints-
- Version
-
- Version version 1709 (Server Core Installation)StatusaffectedConstraints-
- Version version 1803 (Server Core Installation)StatusaffectedConstraints-
- Version
-
- Version (Server Core installation)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 10 | n/a |
| |||||||||||||||
| Microsoft | Windows 10 Servers | n/a |
| |||||||||||||||
| Microsoft | Windows Server 2016 | n/a |
|
OR
- 1607
- 1703
- 1709
- 1803
- n/a
- 1709
- 1803
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.securityfocus.com/bid/104032 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040843 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0961 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/104032 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1040843 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0961 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published May 9, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2017
Link CVE-2018-0961
CISA Vulnrichment
Updated n/a