Executive brief
Windows Hyper-V is a virtualization platform used to run multiple isolated virtual machines on a single server. An authorized local attacker can exploit an untrusted pointer dereference vulnerability to execute arbitrary code with elevated privileges, potentially compromising the underlying host system and all virtual machines running on it.
Technical details
This vulnerability involves an untrusted pointer dereference in Windows Hyper-V, a virtualization hypervisor component. An authorized local attacker can craft malicious input that causes the hypervisor to dereference an unvalidated pointer, leading to code execution with system-level privileges. The attack requires local access and elevated privileges, but successfully exploiting this flaw allows an attacker to break out of virtualization boundaries or gain control of the host system. A security patch is available from Microsoft.
Affected products
- Microsoft Windows Hyper-V
Timeline
- 2026-09-08: disclosed