Executive brief
A security vulnerability has been identified in Microsoft Hyper-V, the virtualization technology used to run multiple operating systems on a single physical server. An attacker who already has limited access to a system could exploit this flaw to gain full administrative control. This could lead to unauthorized access to sensitive data, system instability, or the ability to bypass security restrictions across the virtualized environment.
Technical details
A use-after-free (UAF) vulnerability exists in the Windows Hyper-V hypervisor (CWE-416). The flaw is triggered when the system incorrectly handles objects in memory after they have been deleted or deallocated. An attacker with local access can exploit this condition to execute arbitrary code or gain elevated system privileges. While the attack vector is local, the complexity is rated as high, suggesting specific timing or environmental conditions are required for successful exploitation. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft