CVE Vulnerabilities

CVE-2009-1542

Published: Jul 15, 2009 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability.

Affected Software

Name Vendor Start Version End Version
Virtual_pc Microsoft 2004-sp1 (including) 2004-sp1 (including)
Virtual_pc Microsoft 2007 (including) 2007 (including)
Virtual_pc Microsoft 2007-sp1 (including) 2007-sp1 (including)
Virtual_server Microsoft 2005-r2_sp1 (including) 2005-r2_sp1 (including)

References