CVE-2018-0961: Microsoft Windows 10
High severity, CVSS 7.6. EPSS: 3.2% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Affected products
- Microsoft Windows 10: version 1607 only; version 1703 only; version 1709 only; version 1803 only
- Microsoft Windows Server 2016: affected versions not specified; version 1709 only; version 1803 only
Published 2018-05-09. Last modified 2026-06-17.