Impact
The flaw is an out‑of‑bounds read located within the Windows Hyper‑V virtualization stack. The kernel‑level buffer over‑read can be triggered by a local attacker and allows escalation of privileges to the system level. Because the vulnerability resides in core Hyper‑V code, exploitation can compromise confidentiality, integrity, and availability of the host machine. The weakness is a classic buffer over‑read (CWE‑122) that may also expose sensitive memory contents.
Affected Systems
The vulnerability applies to Windows 10 from version 1607 through 22H2, Windows 11 from 23H2 to 26H1 (both x64 and ARM64 editions), and Windows Server 2016, 2019, 2022, and 2025 including Server‑Core installations. All these releases ship the Hyper‑V component that contains the susceptible code.
Risk and Exploitability
The CVSS score is 8.2, reflecting high severity. The flaw requires local authorization, indicating the likely attack vector is local. No EPSS score is publicly available, so the current exploitation probability remains unknown. The CVE is not listed in the CISA KEV catalogue, suggesting no widespread exploitation has been reported yet. Once triggered, the out‑of‑bounds read enables an attacker to gain full system privileges, providing a pathway for comprehensive system compromise.
OpenCVE Enrichment