Jump to content
Nytro

CVE-2019-0717: Hyper-V vmswitch.sys Out of Bounds Read DoS Vulnerability

Recommended Posts

Posted

Disclosure Note

CVE-2019-0717: Hyper-V vmswitch.sys Out of Bounds Read DoS Vulnerability

I found this bug in 2018 with a custom fuzzer that I wrote as part of the initial reconnaissance of Microsoft Hyper-V architecture and attack vectors. This is a Tier 1 [host OS kernel] vulnerability per the Microsoft's taxonomy, that qualifies for a $50K bounty via the Microsoft Azure Bounty Program.

Credits

Vulnerability discovery and analysis, Proof-of-concept: Alisa Esage [0days.engineer]

 

Sura: https://github.com/badd1e/Disclosures/tree/master/CVE-2019-0717_Hyper-V

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...