Junglewise Threat Intelligence

CVE-2026-32220: Microsoft Windows VBS Enclave security feature bypass

CVE-2026-32220 · Severity: medium · CVSS 4.4 · Published 2026-04-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 25H2, Microsoft Windows Server 2025, Microsoft Windows 11 Version 24H2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security bypass vulnerability exists in the Windows Virtualization-Based Security (VBS) Enclave, a feature used to isolate sensitive data and processes from the rest of the operating system. An attacker who already has high-level administrative access to a machine could exploit this to bypass specific security protections intended to keep data isolated. While this does not allow initial access to a system, it weakens the advanced hardware-based defenses used to protect highly sensitive information.

Technical details

An improper access control vulnerability (CWE-284) exists in the Windows Virtualization-Based Security (VBS) Enclave. The flaw allows a local attacker with high privileges (PR:H) to bypass security feature restrictions within the enclave environment. Exploitation requires local access to the target system and does not require user interaction. Successful exploitation results in a loss of integrity for the security features provided by the VBS enclave, though it does not directly lead to data confidentiality loss or service unavailability according to the CVSS metrics. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 up to 10.0.26100.8246
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 up to 10.0.26200.8246
  • Microsoft Windows 11 version 26H1 10.0.28000.0 up to 10.0.28000.1836
  • Microsoft Windows Server 2025 10.0.26100.0 up to 10.0.26100.32690

Timeline

  • 2026-04-14: disclosed: Initial disclosure by Microsoft
  • 2026-04-14: advisory: NVD publication date

References

Related threats