CVE-2021-28476: Windows Hyper-V Remote Code Execution Vulnerability
Published May 11, 2021
·Updated
Windows Hyper-V Remote Code Execution Vulnerability
Affected Software
18 affected components
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=1607
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Remediation
Event History
May 11, 2021
CVE Published
07:11 PM
Data Sourced
07:11 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-28476?
CVE-2021-28476 is a Windows Hyper-V Remote Code Execution Vulnerability.
2
What software is affected by CVE-2021-28476?
Microsoft Windows 10, Windows 7, Windows 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016, and Windows Server 2019 are affected by CVE-2021-28476.
3
How severe is CVE-2021-28476?
CVE-2021-28476 has a severity rating of 9.9 (critical).
4
What is the proof of concept for CVE-2021-28476?
A proof of concept for CVE-2021-28476 can be found at http://packetstormsecurity.com/files/163497/Microsoft-Hyper-V-vmswitch.sys-Proof-Of-Concept.html.
5
Where can I find more information about CVE-2021-28476?
More information about CVE-2021-28476 can be found at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28476.