Executive brief
Windows Hyper-V is Microsoft's virtualization platform used to run virtual machines in enterprise and cloud environments. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code remotely over the network without authentication, potentially compromising all virtual machines and the host system.
Technical details
The vulnerability is a stack-based buffer overflow in Windows Hyper-V that can be triggered over the network. The flaw allows an unauthenticated attacker to send malicious input that overflows a buffer on the stack, leading to arbitrary code execution. The network-accessible attack vector combined with no authentication requirement means the vulnerability can be exploited by any attacker with network connectivity to the affected system. No public exploitation in the wild has been reported at this time, but patches should be applied immediately given the critical severity.
Affected products
- Microsoft Windows Hyper-V <UNKNOWN>
Timeline
- 2026-09-08: disclosed