CVE-2017-0075
moderate-risk
Published 2017-03-17
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0109.
Do I need to act?
~
4.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.6/10
High
ADJACENT_NETWORK
/ HIGH complexity
Affected Products (11)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/96698
Third Party Advisory
http://www.securityfocus.com/bid/96698
44
/ 100
moderate-risk
Severity
20/34 · Moderate
Exploitability
8/34 · Low
Exposure
16/34 · Moderate