Database/Kernel, userspace & hypervisor

Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wild
CVSS 7.8CVE-2024-38080Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Hyper-V elevation of privilege, exploited in the wild [KEV]
Who can reach it
Local user / guest on the host
What to do
Windows update + host reboot with live-migration
References
Related entries
- Microsoft Hyper-V: Heap-based buffer overflow in the NT Kernel Integration VSPCVE-2025-21333 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21334 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21335 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Linux kernel (drivers/gpu/drm): DRM core stores a pointer to the caller's struct pid before taking a reference on itCVE-2024-39486 · Linux kernel (drivers/gpu/drm)High
- Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the userCVE-2024-40990 · Linux kernel mlx5_ib (shared receive queue)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.