SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1542

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute…

HIGH 9.0EPSS 7.98%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."

CVSS 2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
7.98% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
microsoft/virtual pc · microsoft/virtual server
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.