Junglewise Threat Intelligence

CVE-2026-72961: Microsoft Windows Hyper-V out-of-bounds read privilege escalation

CVE-2026-72961 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

Windows Hyper-V is Microsoft's virtualization platform used to run virtual machines on Windows servers. An authorized attacker with local access to a Hyper-V host system can trigger an out-of-bounds memory read vulnerability that allows them to escalate their privileges to a higher level of system access, potentially compromising the security of all virtual machines and data managed by that host.

Technical details

This vulnerability is an out-of-bounds read in the Windows Hyper-V hypervisor. The flaw allows an authorized local attacker to read memory outside intended boundaries, which can be leveraged to escalate privileges on the Hyper-V host system. The attack requires local access to the host and authenticated privileges to interact with Hyper-V. Exploitation enables privilege escalation from an authenticated local account to a higher privilege level. A patch is available from Microsoft and should be applied as soon as possible to affected systems.

Affected products

  • Microsoft Windows Hyper-V <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats