Executive brief
A heap-based buffer overflow vulnerability in the Microsoft Windows Hyper-V NT Kernel Integration VSP allows a local attacker to escalate privileges to SYSTEM level. The flaw is actively exploited in the wild and affects multiple versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.5371
- Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.5371
- Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.4751
- Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.4751
- Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.2894
- Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1369
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.2894
Timeline
- 2025-01-14: disclosed
- 2025-01-14: patched
- 2025-01-14: kev added: Added to CISA KEV catalog
- 2025-01-14: exploited: Reported as exploited in the wild at time of publication