SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2362

Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by…

HIGH 7.2EPSS 1.62%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by leveraging guest OS privileges, aka "Hyper-V System Data Structure Vulnerability."

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.62% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-254
Affected
microsoft/windows 8 · microsoft/windows 8.1 · microsoft/windows server 2008 · microsoft/windows server 2012
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.