Impact
Heap-based buffer overflow in Windows Hyper‑V allows an authorized attacker to execute code locally within the host operating system. This is a classic heap corruption weakness (CWE‑122) that requires local privileges to exploit.
Affected Systems
The vulnerability affects Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2022 and Microsoft Windows Server 2025 (both full installations and Server Core editions). All affected editions contain the Hyper‑V component that is susceptible to the heap overflow.
Risk and Exploitability
The CVSS score of 8.2 rates this issue as high severity, while the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog. The description does not suggest a remote exploitation path; thus, an attacker would need authorized local access to the Hyper‑V subsystem to exploit the flaw.
OpenCVE Enrichment