Impact
A heap‑based buffer overflow in Windows Hyper‑V can be triggered by an authorized local user, leading to corruption of critical memory structures and elevation of privileges to administrative level. This aligns with CWE‑122, and while the description does not explicitly state it, it is inferred that the attack can compromise the confidentiality, integrity, and availability of the affected system by allowing full control.
Affected Systems
Microsoft Windows 10 1809, 21H2, 22H2; Windows 11 24H2, 25H2, 26H1; Windows Server 2019 (including Server Core), Server 2022, Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score of less than 1% suggests that exploitation is rare but still possible. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker requires local access and can trigger the heap overflow by running code that targets Hyper‑V processes or services, thereby raising his privilege level.
OpenCVE Enrichment