A remote code execution vulnerability exists in Microsoft Hyper-V, affecting Windows Vista SP2, Windows Server 2008 SP2 and R2, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, and 1607, and Windows Server 2016. The vulnerability allows a guest OS user to execute arbitrary code on the host OS by running a specially crafted application within the guest. This vulnerability is distinct from CVE-2017-0109.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) for CVE-2017-0075, a vulnerability in the Microsoft Hyper-V virtual network driver for Linux guests. The structure consists of a custom Linux kernel module (ring0/hyperv/*) that registers a device file (/dev/netvsc_exploit) and exposes IOCTLs for manipulating the Hyper-V network driver. The userland programs (ring3/hyper_v.c and ring3/hyper_v2.c) open this device and issue IOCTLs to trigger specific code paths in the driver, such as blocking/unblocking RNDIS threads and sending keepalive or completion packets. The run.sh script automates the process of removing the standard hv_netvsc module, inserting the custom module, and running the userland exploit. The code is not a full exploit but a PoC that demonstrates the ability to interact with the vulnerable driver and potentially trigger the vulnerability. No remote or network endpoints are present; the attack vector is local, requiring the ability to load kernel modules and execute code on the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.