High SEVERITY — Vulnerability

CVE-2024-21407: Hyper-V remote code execution

Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.

Platform
Windows Server
Version
2022
CVE Record
CVE-2024-21407
CVSS Score
8.1/10
Published
13 February 2024
Views
4
Primary source: Review the official advisory at msrc.microsoft.com Kaynağa Git

Summary

The February 2024 Patch Tuesday update addressed a critical vulnerability in Hyper-V, CVE-2024-21407. An authenticated guest VM user could execute code on the host.

Risk Assessment

Priority is critical for multi-tenant Hyper-V hosts. For single-tenant hosts, the recommended patch window is 7 days.

Windows Server — Related Advisories

VIEW ALL →