Junglewise Threat Intelligence

CVE-2026-45607: Microsoft Hyper-V out-of-bounds read code execution

CVE-2026-45607 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Hyper-V. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows systems. An attacker with local access to a system could exploit this flaw to run unauthorized commands or software. This could lead to a complete takeover of the affected system, potentially compromising sensitive data and disrupting business operations.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within the Microsoft Hyper-V hypervisor. The flaw occurs when the system reads data past the end of the intended buffer, which can be leveraged by a local attacker to achieve arbitrary code execution. The attack vector is local, meaning the attacker must already have a foothold on the system, but it requires no elevated privileges or user interaction. Successful exploitation results in a total loss of confidentiality, integrity, and availability (CVSS 8.4). Users are advised to refer to the Microsoft Security Response Center (MSRC) for official patches and mitigation guidance.

Affected products

  • Microsoft Hyper-V

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats