Windows

Microsoft Windows Hyper-V Exploit Could Not Be Overlooked

An exploit has now emerged for a weak point in the Hyper-V virtualization solution. Microsoft had classified the security problem as uncritical as there was no evidence that the vulnerability was being exploited. That is changing now.

Günter Born reports on his blog. A security update for the “Hyper-V Remote Code Execution Vulnerability – CVE-2021-2847” was released on May Patch Day. A proof-of-concept for the vulnerability was published on Github. This enabled the security researcher Axel Souchet to exploit the error. The newer Windows 10 versions 2004 and 20H2 and their server variants are affected. Souchet showed the exploit on Twitter and made further information available on Github.

To explain what is triggered by the vulnerability, Microsoft has added to the FAQ on the reported security vulnerability and writes :

CVE-2021-2847

  • In what circumstances could this vulnerability be exploited other than through a denial of service attack against a Hyper-V host?
  • This problem allows a guest VM to force the Hyper-V host’s kernel to read from any potentially invalid address. The content of the address read would not be returned to the guest VM. Under most circumstances, this would lead to a refusal of service by the Hyper-V host (bug check) due to reading an unassigned address. It is possible to read from a device register mapped in memory that corresponds to a hardware device attached to the Hyper-V host, which can trigger additional hardware device-specific side effects that could compromise the security of the Hyper-V host.

Host system

Administrators should act accordingly to address the remote code execution vulnerability. The exploit shows how manipulated files could otherwise take over the host system via Hyper-V virtualization. Windows Remote Management (WinRM) and Web Services on Devices (WSDAPI) are also affected by the problem. As far as is known, there is no active exploitation of the security hole (yet).

Recent Posts

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

1 hour ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

1 day ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

1 day ago

Windows 11: Solution for crashing games is distributed automatically

Colorful lights, outdated code and strict anti-cheat software: an unfortunate combination causes massive game crashes…

1 day ago

Plaud One: New in-ear headphones with self-sufficient AI function presented

With the One Explorer Edition, the manufacturer Plaud presents intelligent AI headphones for everyday working…

1 day ago

Can You Trust AI With Your Money? How to Tell a Good Answer From a Confident One

I've written about personal finance for years, and the question readers ask me now has…

1 day ago