Description
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow in Windows Hyper‑V can be triggered by an authorized local user, leading to corruption of critical memory structures and elevation of privileges to administrative level. This aligns with CWE‑122, and while the description does not explicitly state it, it is inferred that the attack can compromise the confidentiality, integrity, and availability of the affected system by allowing full control.

Affected Systems

Microsoft Windows 10 1809, 21H2, 22H2; Windows 11 24H2, 25H2, 26H1; Windows Server 2019 (including Server Core), Server 2022, Server 2025 (including Server Core).

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score of less than 1% suggests that exploitation is rare but still possible. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker requires local access and can trigger the heap overflow by running code that targets Hyper‑V processes or services, thereby raising his privilege level.

Generated by OpenCVE AI on July 31, 2026 at 07:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE-2026-50680 via Windows Update or by downloading the patch from the Microsoft Security Response Center link.
  • If Hyper‑V is not required, disable the feature or restrict its use to trusted administrators to reduce the attack surface.
  • Reboot the system after applying the update to ensure the change is fully deployed and the Hyper‑V components are reinitialized.

Generated by OpenCVE AI on July 31, 2026 at 07:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Title Windows Hyper-V Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:50.459Z

Reserved: 2026-06-05T14:35:07.080Z

Link: CVE-2026-50680

cve-icon Vulnrichment

Updated: 2026-07-15T13:06:41.854Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow