CVE-2017-8714: Microsoft Windows 10

High severity, CVSS 7.8. EPSS: 3.8% chance of exploitation in the next 30 days.

The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Remote Desktop Virtual Host Remote Code Execution Vulnerability".

Affected products

  • Microsoft Windows 10: version 1607 only
  • Microsoft Windows 8.1: any version
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: any version

Published 2017-09-13. Last modified 2026-06-17.