CVE-2024-49117: Windows Hyper-V Remote Code Execution Vulnerability
Published Dec 10, 2024
·Updated
Windows Hyper-V Remote Code Execution Vulnerability
Affected Software
17 affected componentsFixes available
Microsoft Windows Server 2025
Microsoft Windows Server 2025
Microsoft Windows Server 2022, 23H2 Edition
Microsoft Windows 11=23H2
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
Microsoft Windows 11=24H2
Microsoft Windows 11=24H2
Microsoft Windows 11=23H2
Microsoft Windows 11 22h2<10.0.22621.4602
Microsoft Windows 11 23h2<10.0.22631.4602
Microsoft Windows 11 24h2<10.0.26100.2605
Microsoft Windows Server 2022<10.0.20348.2966
Microsoft Windows Server 2022 23h2<10.0.25398.1308
Microsoft Windows Server 2025<10.0.26100.2605
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Event History
Dec 10, 2024
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverity
Dec 12, 2024
Data Sourced
via NVD·02:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49117?
CVE-2024-49117 is classified as a critical remote code execution vulnerability in Windows Hyper-V.
2
How do I fix CVE-2024-49117?
To fix CVE-2024-49117, users should apply the latest security updates provided by Microsoft for their affected systems.
3
Which products are affected by CVE-2024-49117?
CVE-2024-49117 affects multiple versions of Microsoft Windows 11 and Windows Server 2022, as well as future releases like Windows Server 2025.
4
Is CVE-2024-49117 under active exploitation?
As of now, there is no public indication that CVE-2024-49117 is being actively exploited in the wild.
5
What techniques can attackers use to exploit CVE-2024-49117?
Attackers may exploit CVE-2024-49117 by executing arbitrary code on vulnerable Hyper-V hosts resulting in complete system compromise.