Junglewise Threat Intelligence

CVE-2026-40402: Microsoft Windows Hyper-V use after free privilege escalation

CVE-2026-40402 · Severity: critical · CVSS 9.3 · Published 2026-05-12

Technologies: Microsoft Hyper-V. Vendors: Microsoft.

Executive brief

A critical security flaw has been identified in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows systems. This vulnerability allows an attacker who already has basic access to a guest virtual machine to break out of their isolated environment and gain full control over the host server. Such an exploit could lead to a total compromise of all data and services running on that physical hardware, potentially resulting in significant data theft or operational downtime.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Hyper-V hypervisor, tracked as CWE-416. The flaw is triggered when the system continues to use a memory pointer after it has been freed, leading to memory corruption. An attacker with local access to a guest virtual machine can exploit this condition to execute arbitrary code with elevated privileges on the host operating system. The vulnerability is particularly severe because it involves a 'Scope' change (S:C) in the CVSS metric, indicating a successful escape from the virtualized sandbox to the physical host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Hyper-V Windows Server and Windows Desktop versions supporting Hyper-V role

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD.
  • 2026-05-12: patched: Security updates made available via Microsoft Security Update Guide.

References

Related threats