Microsoft Hyper-V VMBus CVE-2011-1872 Denial of Service Vulnerability
BID:48179
Info
Microsoft Hyper-V VMBus CVE-2011-1872 Denial of Service Vulnerability
| Bugtraq ID: | 48179 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1872 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Jun 14 2011 12:00AM |
| Credit: | Nicolas Economou of Core Security Technologies |
| Vulnerable: |
Microsoft Windows Server 2008 R2 for x64-based Systems SP1 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 |
| Not Vulnerable: | |
Discussion
Microsoft Hyper-V VMBus CVE-2011-1872 Denial of Service Vulnerability
Microsoft Hyper-V is prone to a local denial-of-service vulnerability.
Using a guest system, a local attacker can exploit this issue to force the Hyper-V server to become unresponsive, denying service to legitimate users. The denial-of-service conditions would also affect other guest operating systems.
The issue affects Hyper-V on Microsoft Windows Server 2008 and Windows Server 2008 R2.
Microsoft Hyper-V is prone to a local denial-of-service vulnerability.
Using a guest system, a local attacker can exploit this issue to force the Hyper-V server to become unresponsive, denying service to legitimate users. The denial-of-service conditions would also affect other guest operating systems.
The issue affects Hyper-V on Microsoft Windows Server 2008 and Windows Server 2008 R2.
Exploit / POC
Microsoft Hyper-V VMBus 'vmswitch.sys' Denial of Service Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
The following proof-of-concept is available:
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
The following proof-of-concept is available:
Solution / Fix
Microsoft Hyper-V VMBus 'vmswitch.sys' Denial of Service Vulnerability
Solution:
A vendor advisory and updates are available. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2008 for x64-based Systems 0
Solution:
A vendor advisory and updates are available. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2525835)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 481
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2525835)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=26 481
References
Microsoft Hyper-V VMBus 'vmswitch.sys' Denial of Service Vulnerability
References:
References:
- Microsoft Hyper-V Server Homepage (Microsoft)
- Microsoft Security Bulletin MS11-047 - Important (Microsoft)
- MS HyperV Persistent DoS Vulnerability (CORE)