Impact
A heap-based buffer overflow exists in Windows Hyper‑V that can be triggered by a local user with sufficient privileges, allowing that attacker to read memory and expose sensitive data. The flaw is a classic CWE‑122 condition and permits disclosure of internal data that should not be exposed to the operating user. Because the vulnerability is triggered by localized input, it does not provide a path to execute code or modify system state, but it can reveal confidential information useful for further attacks.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2 and 26H1; Microsoft Windows Server 2016, 2019, 2022 and 2025, including Server Core editions.
Risk and Exploitability
The CVSS score of 5 indicates moderate severity. The EPSS score of less than 1% suggests exploitation in the wild is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker with local authorized access can exploit the overflow to leak memory contents; no remote or elevated privilege escape is necessary. The attack requires local access, so restricting local user capabilities reduces risk.
OpenCVE Enrichment