PT-2026-7352 · Microsoft · Windows Hyper-V+1

B2Ahex

+1

·

Published

2026-02-10

·

Updated

2026-06-07

·

CVE-2026-21248

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Hyper-V version 11 25H2 Build 26200.7830
Description A heap-based buffer overflow exists in the dynamic memory component of Windows Hyper-V. This issue allows an authorized attacker to execute arbitrary code locally, potentially leading to privilege escalation on the host and impacting all guest virtual machines. Some reports also indicate that remote attackers may be able to execute arbitrary code and affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

RCE

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-01750
CVE-2026-21248

Affected Products

Windows
Windows Hyper-V