Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in Windows Virtual Machine Bus (VMBus). This vulnerability allows an unauthorized attacker to execute code locally. It affects multiple Windows Server and Windows 10 versions, as well as Windows 11 and Windows Server 2022. The vulnerability arises from a race condition that an attacker must exploit, requiring a high level of complexity.
Exploitation of this vulnerability could lead to remote code execution, allowing an attacker to execute arbitrary code on the affected system.
Users can apply the security updates provided by Microsoft to address this vulnerability. These security updates are available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5058379, KB5058383, KB5058405, KB5058411, KB5058451, KB5058403, KB5058384, and KB5058451.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.