Description
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Published: 2026-06-09
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read in the Hyper‑V virtualization stack that can be triggered by an attacker with local access. The flaw is classified as CWE‑843, an improper array bounds checking weakness, and if successfully exploited it would allow the attacker to execute arbitrary code with the privileges of the Hyper‑V service. The impact is a full compromise of the local system if the attacker is able to run code within the hypervisor context.

Affected Systems

Affected Microsoft products include Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Windows Server builds 2022 and 2025, including Server Core installations. The issue is specific to the Hyper‑V component present on these operating systems.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity and the vulnerability is not listed in CISA’s KEV catalog. EPSS data is not available, so the likelihood of exploitation is currently unknown. The condition for exploitation is local access; the attacker must be able to execute code on the target machine or obtain privileged access to interact with Hyper‑V’s interfaces. Once triggered, the attacker can gain control of the host system with full privileges, potentially enabling further lateral movement.

Generated by OpenCVE AI on June 9, 2026 at 19:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the Microsoft security update that addresses CVE-2026-45641 from the Microsoft Update Catalog or Windows Update.
  • Restart the affected systems so that the patched kernel image is loaded and the vulnerability is fully mitigated.
  • Verify that the Hyper‑V service runs with the minimum privileges required for deployment and review hypervisor access controls to limit unnecessary local access.

Generated by OpenCVE AI on June 9, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Title Windows Hyper-V Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-843
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 21h2 Windows 10 22h2 Windows 10 22h2 Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-10T10:27:49.152Z

Reserved: 2026-05-12T20:33:35.156Z

Link: CVE-2026-45641

cve-icon Vulnrichment

Updated: 2026-06-10T10:27:43.491Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:31.100

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T11:15:05Z

Weaknesses