Executive brief
Microsoft Windows Hyper-V contains an elevation of privilege vulnerability caused by an integer overflow. A local attacker with user-level permissions can exploit this flaw to gain SYSTEM privileges on the affected host.
Affected products
- Microsoft Windows 11 21H2 up to (excluding) 10.0.22000.3079
- Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.3880
- Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.3880
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2582
- Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1009
Timeline
- 2024-07-09: disclosed
- 2024-07-09: patched
- 2024-07-09: kev added: Added to CISA KEV catalog due to active exploitation.
- 2024-07-09: exploited