Description
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Patch Now
AI Analysis

Impact

An untrusted pointer dereference in Windows Hyper‑V can allow an authorized local user to execute arbitrary code. The flaw arises because the Hyper‑V hypervisor incorrectly verifies the pointer before dereferencing, leading to uncontrolled code execution. As a result, an attacker who has local access can gain elevated privileges and run malicious code with kernel‑level authority, potentially compromising system confidentiality, integrity, and availability.

Affected Systems

Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2022 and 2025 (including Server Core installations) are listed as affected. The vulnerability applies to both ARM64 and x64 builds of Windows 11 in the specified releases, as well as all architectures of Windows Server 2025 and the ARM64/x64 builds of Windows 11 23H2. Any host running these operating system versions without the vendor security update is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 ranks this vulnerability as high severity, and the absence of an EPSS score indicates that current weaponized exploitation data is not publicly available, but the flaw remains significant. It is not listed in the CISA KEV catalog. Attackers would need local access to the host; there is no remote exploitation path disclosed or implied in the description. Once the flaw is triggered, arbitrary code can be executed within the Hyper‑V context, leading to full system compromise.

Generated by OpenCVE AI on September 9, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update that addresses CVE‑2026‑80083 from the Microsoft security update guide.
  • If the update cannot be applied immediately, disable or restrict the Hyper‑V service on the host to prevent the vulnerability from being exploitable.
  • As a temporary containment measure, isolate the vulnerable host from the network and monitor for anomalous Hyper‑V or kernel‑mode activity using Windows event logs.

Generated by OpenCVE AI on September 9, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
Title Windows Hyper-V Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:48.183Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80083

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:16.886Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:50.613

Modified: 2026-09-10T15:14:14.580

Link: CVE-2026-80083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:05:24Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference