Executive brief
A critical security flaw has been identified in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows systems. This vulnerability allows an attacker who already has basic access to a guest virtual machine to break out of their isolated environment and gain full control over the host server. Such an exploit could lead to a total compromise of all data and services running on that physical hardware, potentially resulting in significant data theft or operational downtime.
Technical details
A use-after-free (UAF) vulnerability exists in the Windows Hyper-V hypervisor, tracked as CWE-416. The flaw is triggered when the system continues to use a memory pointer after it has been freed, leading to memory corruption. An attacker with local access to a guest virtual machine can exploit this condition to execute arbitrary code with elevated privileges on the host operating system. The vulnerability is particularly severe because it involves a 'Scope' change (S:C) in the CVSS metric, indicating a successful escape from the virtualized sandbox to the physical host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Hyper-V Windows Server and Windows Desktop versions supporting Hyper-V role
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD.
- 2026-05-12: patched: Security updates made available via Microsoft Security Update Guide.