Junglewise Threat Intelligence

CVE-2026-42972: Microsoft Windows Hyper-V information disclosure

CVE-2026-42972 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Hyper-V. Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Hyper-V, the software used to run virtual machines on Windows, could allow an authorized user to access sensitive information they should not be able to see. To exploit this, an attacker must already have local access to the system. While this does not allow for remote control of the computer, it could lead to the exposure of confidential data or system secrets.

Technical details

Microsoft Hyper-V is vulnerable to an information disclosure flaw (CWE-200) when it fails to properly handle sensitive data in memory or storage. An attacker with local access and low-level privileges (PR:L) can exploit this vulnerability to read unauthorized information. The attack vector is local, meaning the attacker must have the ability to execute code on the host or a guest partition. Successful exploitation results in high confidentiality impact but does not directly affect system integrity or availability. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Hyper-V Windows Server and Windows Desktop versions supporting Hyper-V

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Microsoft published the security advisory and update guide.

References

Related threats