Microsoft Windows Server 2008
cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*, +1 more
- >= 6.0.6003.23418, < 6.0.6003.23419
A remote code execution vulnerability has been identified in the Virtual Hard Disk (VHDX) component of Microsoft Windows. This issue arises from an integer overflow or wraparound, which allows an unauthorized attacker to execute code locally. The vulnerability affects several versions of Windows Server 2008, 2008 R2, 2012, and 2012 R2.
Exploitation of this vulnerability could lead to remote code execution on affected systems running Windows Server 2008, but only cause a denial-of-service on systems with Windows Server 2008 R2 or newer.
Users can apply the security updates provided by Microsoft. These can be downloaded via the Microsoft Update Catalog or through the Windows Server Update Services (WSUS).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.