Executive brief
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability. A local attacker can exploit this flaw to escalate privileges to SYSTEM level. This vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 Version 21H2 up to (excluding) 10.0.19044.5371
- Microsoft Windows 10 Version 22H2 up to (excluding) 10.0.19045.5371
- Microsoft Windows 11 Version 22H2 up to (excluding) 10.0.22621.4751
- Microsoft Windows 11 Version 23H2 up to (excluding) 10.0.22631.4751
- Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.2894
- Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1369
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.2894
Timeline
- 2025-01-14: disclosed
- 2025-01-14: patched
- 2025-01-14: kev added: Added to CISA KEV catalog due to active exploitation.
- 2025-01-14: exploited