Impact
A missing authorization check in Windows Hyper‑V allows an authorized attacker to gain higher privileges over a network. The flaw enables an attacker who can interact with Hyper‑V management interfaces to elevate their access rights, potentially granting them system‑level control without the need for initial administrative credentials. This could be used to compromise host security and persist on the affected system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2019 (including Server Core), 2022, and 2025 (including Server Core). The vulnerability applies to the default Hyper‑V build present in these releases.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, indicating a high impact if exploited. EPSS data is not available, so exact exploitation probability is uncertain, and the flaw has not yet been listed in the CISA KEV catalog. The likely attack vector is a network‑based privileged attacker who can access Hyper‑V management channels; no local privilege or code execution prerequisites are described beyond existing authorized access to the host. Given the lack of a publicly disclosed exploit yet, the risk remains primarily theoretical, but the high severity and network exposure warrant active mitigation as soon as the vendor’s patch is available.
OpenCVE Enrichment