Executive brief
A security vulnerability exists in Microsoft Hyper-V, the software used to create and manage virtual machines on Windows. An attacker who already has basic access to a system could exploit this flaw to gain higher-level administrative permissions. This could allow them to take full control of the affected machine, potentially compromising sensitive data or disrupting operations.
Technical details
This vulnerability is classified as a Use-After-Free (CWE-416) within the Windows Hyper-V component. An attacker must first gain local access to the target system with low-level privileges. By exploiting a race condition or improper memory management during Hyper-V operations, the attacker can trigger the use of a memory pointer after it has been freed, leading to arbitrary code execution in a higher-privileged context. The attack complexity is rated as high, suggesting specific timing or environmental conditions are required for successful exploitation. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory