Windows Hyper-V Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-42972Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Windows Hyper-V contains an information disclosure vulnerability that allows an authorized local user to access sensitive information from the hypervisor. This could expose virtual machine configuration data, credentials, or memory contents. Exploitation requires valid local credentials and direct access to the Hyper-V host system.
What this means
What could happen
An authenticated local user could read sensitive information from the Hyper-V hypervisor, potentially exposing virtual machine secrets, memory data, or configuration details. This is a low-risk information disclosure that does not directly affect OT operations but could compromise the security posture of virtualized control systems.
Who's at risk
Organizations running Hyper-V virtualization on Windows Server 2016, 2019, 2022, 2025, or Windows 10/11 desktop systems should prioritize this update. Critical for facilities that use virtualized engineering workstations, SCADA servers, or other control systems running on Hyper-V. Less urgent for organizations without Hyper-V deployments.
How it could be exploited
An attacker with local administrator or authorized user credentials on a Windows system running Hyper-V could exploit the information disclosure vulnerability through direct access to the hypervisor, allowing them to extract sensitive data from running virtual machines without affecting their execution.
Prerequisites
- Local access to a Windows system with Hyper-V role enabled
- Valid local user credentials with authorization to interact with Hyper-V
- System must be running a vulnerable Windows version listed in the advisory
Local access requiredAuthentication requiredLow EPSS score (<1%)No active exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (20)
20 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/5Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9234 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.8880 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5256 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.32995 or later
All products
HOTFIXUpdate Windows 10 and Windows 11 systems to the corresponding fixed builds listed in the advisory
Long-term hardening
0/1HARDENINGRestrict local administrative access to Hyper-V hosts to only necessary personnel
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b69cce15-e893-4179-bfe3-28f481a3d56cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.