Impact
The updated description confirms a type‑confusion vulnerability in Windows Hyper‑V, where an incompatible type is used to access a resource, allowing an attacker to execute arbitrary code locally on the host. The flaw is classified as CWE‑125 and CWE‑843, and permits local code execution with the privileges of the local user.
Affected Systems
Affected Microsoft products Windows 10 21H2, 22H2, Windows 11 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core). The issue is specific to the Hyper‑V virtualization component present in these operating systems.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity vulnerability, and the EPSS score of less than 1% indicates that exploitation is believed to be rare. It is not currently listed in the CISA KEV catalog. The flaw requires local access; based on the description, the attacker must be able to invoke Hyper‑V interfaces or otherwise trigger the type‑confusion. The vulnerability permits local code execution, potentially allowing arbitrary code to run with the privileges of the local user with Hyper‑V services, but this inference is drawn from the official Microsoft description rather than explicit documentation of an attacker path.
OpenCVE Enrichment