SB2017031487 - Hyper-V vSMB Remote Code Execution Vulnerability
Published: March 14, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2017-0021)
The vulnerability allows a remote attacker with access to guest operating system to execute arbitrary code on the host system.
The vulnerability exists due to input validation error when processing SMB packets in Windows Hyper-V. A remote attacker with access to guest system can send specially crafted SMB packets to the host system and execute arbitrary code on the host system.
Successful exploitation of this vulnerability may allow an attacker to compromise the host system.
Remediation
Install update from vendor's website.