CVE-2019-0723

Description

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash.The update addresses the vulnerability by modifying how virtual machines access the Hyper-V Network Switch.

Risk Information

Base Score
4.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
1.229

Associated Vulnerability

VulnerabilityOS Platform
Win32k Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4512486)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4512486)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4512486)Windows
Windows Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4512489)Windows
Windows Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4512489)Windows
Windows Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4512489)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4512482)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4512488)Windows
Windows Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4512488)Windows
Windows Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4512488)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4512501)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4512516)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4512508)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4512517)Windows
Windows Information Disclosure Vulnerability for Windows Server 2019 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4511553)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4511553)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4512518)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4512506)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4512506)Windows
Windows ALPC Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4512506)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4512497)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4512507)Windows
Windows Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4512507)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-271952019-08 Security Only Quality Update for Windows 7 for x64-based Systems (KB4512486)
PATCH-271962019-08 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4512486)
PATCH-271972019-08 Security Only Quality Update for Windows 7 for x86-based Systems (KB4512486)
PATCH-271982019-08 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4512489)
PATCH-271992019-08 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4512489)
PATCH-272002019-08 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4512489)
PATCH-272032019-08 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4512482)
PATCH-272142019-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4512517)
PATCH-272352019-08 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4512488)
PATCH-272362019-08 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4512488)
PATCH-272372019-08 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4512488)
PATCH-272232019-08 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4512501)
PATCH-272242019-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4512501)
PATCH-272252019-08 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4512501)
PATCH-272212019-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4512516)
PATCH-272222019-08 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4512516)
PATCH-272292019-08 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4512508)
PATCH-272302019-08 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4512508)
PATCH-272312019-08 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4512508)
PATCH-272152019-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4512517)
PATCH-272162019-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4512517)
PATCH-272262019-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4511553)
PATCH-272272019-08 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4511553)
PATCH-272282019-08 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4511553)
PATCH-272402019-08 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4512518)
PATCH-272322019-08 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4512506)
PATCH-272332019-08 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4512506)
PATCH-272342019-08 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4512506)
PATCH-272172019-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4512497)
PATCH-272182019-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4512497)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234