Impact
Windows Hyper‑V contains a heap‑based buffer overflow that allows an attacker with local access to the Hyper‑V virtualization stack to execute code within the system. The flaw is a classic heap corruption weakness (CWE‑122). No remote trigger is evident from the description, so the danger manifests when an attacker can run code within the Hyper‑V environment on the target machine.
Affected Systems
The vulnerability affects Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2022 and Microsoft Windows Server 2025 (both full installations and Server Core editions). All affected editions contain the Hyper‑V component that is susceptible to the heap overflow.
Risk and Exploitability
The CVSS score of 8.2 rates this issue as high severity, while the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog. The description does not suggest a remote exploitation path; thus, an attacker would need authorized local access to the Hyper‑V subsystem to exploit the flaw.
OpenCVE Enrichment