Windows Hyper-V Elevation of Privilege Vulnerability
Plan PatchCVSS 8.2CVE-2026-50680Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability in Windows Hyper-V allows an authorized attacker with administrator credentials to elevate privileges on the hypervisor host. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 across multiple architectures (32-bit, x64, ARM64). Microsoft has released patches for all affected versions and rates exploitation as less likely.
What this means
What could happen
An authorized administrator on a Hyper-V host could exploit a buffer overflow in the hypervisor to gain system-level privileges and potentially access or disrupt virtual machines running on that host.
Who's at risk
System administrators and operators managing Windows Hyper-V environments, including those running virtualized industrial control systems, SCADA platforms, or critical process control software in virtual machines on Windows Server 2019, 2022, or 2025, and Windows 10/11 systems with Hyper-V enabled.
How it could be exploited
An attacker with administrator credentials on a Windows Hyper-V host could trigger a heap-based buffer overflow in the Hyper-V kernel component through a crafted operation. This allows the attacker to escalate from administrator to system-level privileges, gaining full control of the hypervisor and all VMs it runs.
Prerequisites
- Administrator or high-privilege account on the Hyper-V host
- Local access or remote access as an authenticated administrator
- Windows Hyper-V role enabled on the target system
requires high privilegelocal or authenticated remote exploitationlow complexityaffects virtualization infrastructureno active exploitation reported
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul Microsoft security update to all Windows 10, Windows 11, and Windows Server systems running Hyper-V
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a2d76d13-5e7a-4323-828e-82dcf0bdeca1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.