« Volver al listado

CVE-2025-29955

Estado: AnalizadaMedia (5.5)—

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-29955",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-29955",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-13T17:58:16.717922Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Windows 11 Version 24H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4061",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.25398.0",
              "lessThan": "10.0.25398.1611",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2025",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4061",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2025 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4061",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        }
      ]
    }
  ],
  "published": "2025-05-13T17:15:55.477",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29955",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally."
    },
    {
      "lang": "es",
      "value": "La validación de entrada incorrecta en Windows Hyper-V permite que un atacante no autorizado deniegue el servicio localmente."
    }
  ],
  "lastModified": "2026-06-17T09:05:57.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "7CE8E58A-59AA-4649-8C0F-0DB11A1D1936",
              "versionEndExcluding": "10.0.26100.4061"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B9B2720-3733-4C50-85F7-156D781D15B8",
              "versionEndExcluding": "10.0.25398.1611"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAE51E4F-FCFF-4DC0-9B76-861EE20D54A4",
              "versionEndExcluding": "10.0.26100.4061"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}