Junglewise Threat Intelligence

CVE-2026-50680: Microsoft Windows Hyper-V heap overflow privilege escalation

CVE-2026-50680 · Severity: high · CVSS 8.2 · Published 2026-07-14

Technologies: Microsoft Windows Hyper-V, Microsoft Hyper-V, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows systems. An attacker who already has high-level administrative access to a guest virtual machine could exploit this flaw to break out of their isolated environment and gain control over the host physical server. This could lead to a total compromise of the host system, including access to data from other virtual machines running on the same hardware.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows Hyper-V hypervisor. The vulnerability is triggered locally by an attacker with high privileges (PR:H) on a guest operating system. By exploiting this memory corruption issue, the attacker can achieve a virtual machine escape, leading to a scope change (S:C) where they can execute arbitrary code with the privileges of the host system. This impacts the confidentiality, integrity, and availability of the entire host environment. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1809 / 21H2 / 22H2 Multiple versions prior to July 2026 updates
  • Microsoft Windows 11 Version 24H2 / 25H2 / 26H1 Multiple versions prior to July 2026 updates
  • Microsoft Windows Server 2019 / 2022 Multiple versions prior to July 2026 updates
  • Microsoft Windows Hyper-V

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats