CVE-2019-1397 is a remote code execution vulnerability in Windows Hyper-V, affecting various Windows client and server operating systems. It arises from improper input validation by the host server when processing data from an authenticated guest operating system. With a CVSS score of 8.4 (High), this vulnerability allows an authenticated attacker on a guest OS to execute arbitrary code on the Hyper-V host, leading to significant impact on confidentiality, integrity, and availability. While the vulnerability has garnered some media attention and community discussion, there is currently no public exploit code available, nor is it listed in CISA's KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:x64:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:x64:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.