Executive brief
A vulnerability in Microsoft Hyper-V, the software used to create and manage virtual machines, could allow an authorized user to cause a system crash or service outage. To exploit this, an attacker must already have high-level permissions and be located on the same local network as the target system. While this does not allow for data theft, it can disrupt business operations by taking critical virtualized servers offline.
Technical details
A buffer over-read vulnerability (CWE-126) exists in Microsoft Hyper-V. The flaw is triggered when the system attempts to read data beyond the boundaries of an allocated buffer, leading to a crash of the host or the virtualization service. Exploitation requires the attacker to have high privileges (PR:H) and be positioned on an adjacent network (AV:A), such as the same local subnet or logical link. Successful exploitation results in a denial-of-service (DoS) but does not provide a path for information disclosure or code execution. Microsoft has released security updates to address this issue across various Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
- Microsoft Hyper-V All versions on affected Windows OS
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft
- 2026-07-14: advisory: NVD record published