CVE-2009-1542 describes a critical vulnerability in Microsoft Virtual PC and Virtual Server products where the Virtual Machine Monitor (VMM) fails to enforce CPU privilege-level requirements. This flaw allows a malicious guest OS user to execute arbitrary kernel-mode code within the guest OS, leading to privilege escalation. With a CVSS score of 9.0, this vulnerability is highly severe, requiring authenticated access but allowing for complete compromise of confidentiality, integrity, and availability within the guest. While no public exploit intelligence or active exploitation is noted, its high FAUCET Risk Score indicates significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:virtual_pc:2004:sp1:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:virtual_pc:2007:*:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:virtual_pc:2007:*:x64:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:virtual_pc:2007:sp1:*:*:*:*:*:* | ||
2005CPE matchmatch criteria | cpe:2.3:a:microsoft:virtual_server:2005:r2_sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.