CVE-2024-21407: Hyper-V remote code execution
Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.
Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.
The February 2024 Patch Tuesday update addressed a critical vulnerability in Hyper-V, CVE-2024-21407. An authenticated guest VM user could execute code on the host.
Priority is critical for multi-tenant Hyper-V hosts. For single-tenant hosts, the recommended patch window is 7 days.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.