Windows Hyper-V Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-42972Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Windows Hyper-V contains an information disclosure vulnerability that allows an authorized local user to access sensitive information from the hypervisor. This could expose virtual machine configuration data, credentials, or memory contents. Exploitation requires valid local credentials and direct access to the Hyper-V host system.

What this means
What could happen
An authenticated local user could read sensitive information from the Hyper-V hypervisor, potentially exposing virtual machine secrets, memory data, or configuration details. This is a low-risk information disclosure that does not directly affect OT operations but could compromise the security posture of virtualized control systems.
Who's at risk
Organizations running Hyper-V virtualization on Windows Server 2016, 2019, 2022, 2025, or Windows 10/11 desktop systems should prioritize this update. Critical for facilities that use virtualized engineering workstations, SCADA servers, or other control systems running on Hyper-V. Less urgent for organizations without Hyper-V deployments.
How it could be exploited
An attacker with local administrator or authorized user credentials on a Windows system running Hyper-V could exploit the information disclosure vulnerability through direct access to the hypervisor, allowing them to extract sensitive data from running virtual machines without affecting their execution.
Prerequisites
  • Local access to a Windows system with Hyper-V role enabled
  • Valid local user credentials with authorization to interact with Hyper-V
  • System must be running a vulnerable Windows version listed in the advisory
Local access requiredAuthentication requiredLow EPSS score (<1%)No active exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (20)
20 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9234 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.8880 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5256 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.32995 or later
All products
HOTFIXUpdate Windows 10 and Windows 11 systems to the corresponding fixed builds listed in the advisory
Long-term hardening
0/1
HARDENINGRestrict local administrative access to Hyper-V hosts to only necessary personnel
API: /api/v1/advisories/b69cce15-e893-4179-bfe3-28f481a3d56c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Hyper-V Information Disclosure Vulnerability | CVSS 5.5 - OTPulse