Impact
Heap-based buffer overflow in the Hyper‑V virtualization engine on Windows can allow an attacker who has authorized access to the host to execute arbitrary code locally within the Hyper‑V process. This flaw, identified as CWE‑122, carries a CVSS score of 8.8, indicating a high potential impact if exploited. Successful exploitation would grant the attacker control over the host system and any virtual machines running on that host.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2; and Windows Server 2012 through 2025, including both full and Server Core installations, on x86, x64, and ARM architectures.
Risk and Exploitability
Because the flaw is local, an attacker must already possess some level of access to the Hyper‑V host, such as a privileged user or a compromised guest. No exploit probability score is available and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score underscores that any successful local exploitation would provide the attacker with broad control over the host and all virtual machines it hosts, posing a significant risk to confidentiality, integrity, and availability.
OpenCVE Enrichment