CVE-2020-0909

Executive Summary

A denial‑of‑service flaw in Hyper‑V on Windows Server allows an attacker to send crafted network packets that cause the hypervisor to crash or become unresponsive. The vulnerability can be triggered remotely over the network, leading to service disruption for virtual machines and host systems. Microsoft released a patch that corrects the packet‑handling logic to prevent the crash.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2020-05-21T23:15:11.273 - Last Modified: 2026-08-19T17:17:07.417

Original Description: A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets.

"Bodily exercise, when compulsory, does no harm to the body; but knowledge which is acquired under compulsion obtains no hold on the mind."

— Plato
Source: NVD