02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: microsoftAn information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 2.44% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 83.1% of scored records. A rank, not a probability.
- NVD base score
- 6.2 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2019-03-06 00:00Z7 YR AGO
- Last updated
- 2024-08-04 17:51Z2 YR AGO
- Reserved
- 2018-11-26
- Assigning CNA
- microsoft
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- CWE-20Improper Input ValidationClass
- Data version
- 5.1
- Document digest
- 74440cb68f834d19af1bbc09420f6590211a0cc0524bdebd78bab270bac03f7d
05 Affected products
PAIRS: 2VendorProductVersionsPlatforms
MicrosoftWindows7 for x64-based Systems Service Pack 1, 8.1 for x64-based systems, 10 for x64-based Systems, 10 Version 1607 for x64-based Systems, 10 Version 1703 for x64-based Systems, 10 Version 1709 for x64-based Systems, 10 Version 1803 for x64-based Systems, 10 Version 1809 for x64-based Systems— MicrosoftWindows Server2008 R2 for x64-based Systems Service Pack 1 (Core installation), 2008 R2 for x64-based Systems Service Pack 1, 2012, 2012 (Core installation), 2012 R2, 2012 R2 (Core installation), 2016, 2016 (Core installation), version 1709 (Core Installation), version 1803 (Core Installation), 2019, 2019 (Core installation), 2008 for x64-based Systems Service Pack 2, 2008 for x64-based Systems Service Pack 2 (Core installation)—