Executive brief
Microsoft Hyper-V is a virtualization platform that allows multiple operating systems to run on a single physical server. A security flaw in this component could allow a user with high privileges on a guest virtual machine to break out and execute malicious code on the underlying host system. This could lead to a complete compromise of the server, impacting all other virtual machines and sensitive data stored on the host.
Technical details
A heap-based buffer overflow (CWE-122) exists in Windows Hyper-V due to an out-of-bounds read flaw. The vulnerability is triggered locally by an attacker who already possesses high privileges (PR:H) on a guest virtual machine. By exploiting this memory corruption issue, the attacker can achieve a virtual machine escape, leading to arbitrary code execution on the host operating system (Scope: Changed). Microsoft has released security updates to address this vulnerability via the MSRC update guide.
Affected products
- Microsoft Hyper-V
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory