Windows Hyper-V Denial of Service Vulnerability
MonitorCVSS 4.5CVE-2026-50485Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary
A buffer over-read vulnerability in Windows Hyper-V allows an authorized attacker on an adjacent network to cause a denial of service condition. The vulnerability requires administrative or Hyper-V-specific credentials and affects Windows Server 2016, 2019, 2022, 2025 and Windows 10/11 systems with Hyper-V enabled. Exploitation is assessed as less likely.
What this means
What could happen
An authorized attacker on the same network segment could crash or hang a Hyper-V host, disrupting all virtual machines running on that host and any services they support.
Who's at risk
Organizations running Hyper-V virtualization on Windows Server (2016, 2019, 2022, 2025) or Windows 10/11 client systems should be concerned. This includes data centers, private cloud environments, and any facilities using Microsoft virtualization for industrial automation, SCADA systems, or operational technology network segmentation.
How it could be exploited
An attacker with administrative privileges or Hyper-V-specific credentials on the same network (adjacent network) sends a crafted request to the Hyper-V service that triggers a buffer over-read, causing the service to become unresponsive or crash.
Prerequisites
- Administrative or Hyper-V-specific credentials
- Network access to the Hyper-V host from an adjacent network segment
- Hyper-V role enabled on Windows Server or virtualization feature on Windows 10/11
requires high privilegesrequires adjacent network accessaffects availability (denial of service)low exploitation likelihood
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict network access to Hyper-V management ports to authorized administrative users and networks only; use firewall rules to block untrusted network access to the Hyper-V host
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the July 2026 Microsoft security update to all Windows Server 2016, 2019, 2022, 2025, and Windows 10/11 systems running Hyper-V
Long-term hardening
0/1HARDENINGLimit Hyper-V administrative credentials to a small group of trusted administrators; enforce strong password policies and MFA for accounts with Hyper-V permissions
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/55fcaaf5-b1c5-4bca-ac7c-0a1e31a92843Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.