CVE-2020-0909: Windows Hyper-V Denial of Service Vulnerability
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets.
Other sources
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets.To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets., aka 'Windows Hyper-V Denial of Service Vulnerability'.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853
Event History
Frequently Asked Questions
Which systems are identified as affected?
The listed affected software includes Microsoft Windows 7, Windows 10, Windows Server 2008, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019 where Hyper-V is in use.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network attack vector, low attack complexity, no privileges required, and no user interaction required.
What is the expected impact of successful exploitation?
Successful exploitation can cause a denial of service. The provided CVSS vector indicates high availability impact, with no stated confidentiality or integrity impact.
What remediation is identified?
Apply the security update referenced for CVE-2020-0909. The update resolves the Hyper-V packet-handling conditions that cause the denial of service.