CERT-In Vulnerability Note
CIVN-2021-0259
Remote Code Execution Vulnerability in Microsoft Windows Hyper-V
Original Issue Date:October 14, 2021
Severity Rating: HIGH
Software Affected
- Microsoft Windows Server 2019
- Microsoft Windows 10 1809 for x64-based Systems
- Microsoft Windows 10 2004 for x64-based Systems
- Microsoft Windows 10 1909 for ARM64-based Systems
- Microsoft Windows 10 20H2 for x64-based Systems
- Microsoft Windows Server (Server Core installation) 2019
- Microsoft Windows Server (Server Core installation) 2004
- Microsoft Windows Server (Server Core installation) 20H2
- Microsoft Windows 10 21H1 for x64-based Systems
- Microsoft Windows Server (Server Core installation) 2022
- Microsoft Windows 11 x64
- Microsoft Windows Server 2022
Overview
A vulnerability has been reported in Microsoft Windows Hyper-V which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in Microsoft Windows Hyper-V due to improper input validation in Windows Hyper-V. A remote attacker could exploit this vulnerability by sending a specially-crafted request and execute arbitrary code on the targeted system.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Install appropriate security updates from vendor website.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40461
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38672
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40461
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38672
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40461
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38672
CyberSecurityHelp
https://www.cybersecurity-help.cz/vdb/SB2021101247
CVE Name
CVE-2021-40461
CVE-2021-38672
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|