CVE-2017-8707: Infoleak
The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8706, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the affected Windows versions with the Hyper-V component are exposed, including Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 and 2012 R2, specified Windows 10 releases, and Windows Server 2016. Exploitation involves a guest operating system.
What access does an attacker need?
An attacker must be authenticated on a guest operating system and must successfully provide input that Hyper-V fails to validate properly. The CVSS vector indicates local access, high privileges, and high attack complexity are required.
What is the impact if exploitation succeeds?
Successful exploitation can disclose information. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
Is a fix available?
Yes. A patch is available for this vulnerability.