Vulnerability Name: | CVE-2013-3898 (CCN-88369) | ||||||||
Assigned: | 2013-11-12 | ||||||||
Published: | 2013-11-12 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability." | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.9 High (CVSS v2 Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-3898 Source: CCN Type: SA55550 Microsoft Windows Hyper-V Hypercall Function Parameter Handling Vulnerability Source: CCN Type: Microsoft Security Bulletin MS13-092 Vulnerability in Hyper-V Could Allow Elevation of Privilege (2893986) Source: CCN Type: BID-63562 Microsoft Windows Hyper-V CVE-2013-3898 Local Privilege Escalation Vulnerability Source: CERT Type: US Government Resource TA13-317A Source: MS Type: UNKNOWN MS13-092 Source: XF Type: UNKNOWN ms-hyperv-cve20133898-priv-esc(88369) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:18851 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |