CVE-2017-0109: Input Validation
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0075.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0109?
CVE-2017-0109 has a critical severity rating as it allows arbitrary code execution on the host OS by guest OS users.
How do I fix CVE-2017-0109?
To fix CVE-2017-0109, apply the latest security updates provided by Microsoft for your affected Windows version.
Which operating systems are affected by CVE-2017-0109?
CVE-2017-0109 affects various versions of Microsoft Windows including Windows Vista, 7, 8.1, 10, and several Server editions.
What is the impact of CVE-2017-0109?
The impact of CVE-2017-0109 is that it allows guest OS users to execute arbitrary code on the host OS, compromising system integrity.
Is CVE-2017-0109 exploited in the wild?
There have been reports indicating that CVE-2017-0109 may be exploited by attackers, making it crucial to apply the necessary patches.