Impact
An untrusted pointer dereference in Windows Hyper‑V can allow an authorized local user to execute arbitrary code. The flaw arises because the Hyper‑V hypervisor incorrectly verifies the pointer before dereferencing, leading to uncontrolled code execution. As a result, an attacker who has local access can gain elevated privileges and run malicious code with kernel‑level authority, potentially compromising system confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2022 and 2025 (including Server Core installations) are listed as affected. The vulnerability applies to both ARM64 and x64 builds of Windows 11 in the specified releases, as well as all architectures of Windows Server 2025 and the ARM64/x64 builds of Windows 11 23H2. Any host running these operating system versions without the vendor security update is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 ranks this vulnerability as high severity, and the absence of an EPSS score indicates that current weaponized exploitation data is not publicly available, but the flaw remains significant. It is not listed in the CISA KEV catalog. Attackers would need local access to the host; there is no remote exploitation path disclosed or implied in the description. Once the flaw is triggered, arbitrary code can be executed within the Hyper‑V context, leading to full system compromise.
OpenCVE Enrichment