Impact
The vulnerability involves accessing a resource using an incompatible type, referred to as type confusion, in the Windows Hyper‑V component. This flaw enables an unauthorized attacker to execute code locally on the host and is classified as CWE‑125 and CWE‑843.
Affected Systems
Affected Microsoft products include Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Windows Server builds 2022 and 2025, including Server Core installations. The issue is specific to the Hyper‑V component present on these operating systems.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity flaw, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates that the likelihood of exploitation is very low, but not zero. The condition for exploitation is local access; the attacker must be able to invoke Hyper‑V interfaces or otherwise trigger the type‑confusion. The flaw permits local code execution, potentially allowing the attacker to execute arbitrary code on the host with the privileges of the local user.
OpenCVE Enrichment