Junglewise Threat Intelligence

CVE-2026-45641: Microsoft Hyper-V code execution via type confusion

CVE-2026-45641 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Hyper-V. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows systems. An attacker with local access to a system could exploit this flaw to run unauthorized code with high privileges. This could lead to a complete takeover of the affected host system, potentially compromising all data and virtualized services running on it.

Technical details

This vulnerability is characterized as a type confusion (CWE-843) and out-of-bounds read within the Microsoft Hyper-V hypervisor. The flaw allows an unauthorized local attacker to bypass memory safety protections. By exploiting this issue, an attacker can achieve arbitrary code execution in the context of the host operating system. The attack vector is local, meaning the attacker must already have a presence on the system, but it requires no elevated privileges or user interaction to execute. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Hyper-V

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats