Windows Hyper-V Elevation of Privilege Vulnerability

Plan PatchCVSS 8.2CVE-2026-50680Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability in Windows Hyper-V allows an authorized attacker with administrator credentials to elevate privileges on the hypervisor host. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 across multiple architectures (32-bit, x64, ARM64). Microsoft has released patches for all affected versions and rates exploitation as less likely.

What this means
What could happen
An authorized administrator on a Hyper-V host could exploit a buffer overflow in the hypervisor to gain system-level privileges and potentially access or disrupt virtual machines running on that host.
Who's at risk
System administrators and operators managing Windows Hyper-V environments, including those running virtualized industrial control systems, SCADA platforms, or critical process control software in virtual machines on Windows Server 2019, 2022, or 2025, and Windows 10/11 systems with Hyper-V enabled.
How it could be exploited
An attacker with administrator credentials on a Windows Hyper-V host could trigger a heap-based buffer overflow in the Hyper-V kernel component through a crafted operation. This allows the attacker to escalate from administrator to system-level privileges, gaining full control of the hypervisor and all VMs it runs.
Prerequisites
  • Administrator or high-privilege account on the Hyper-V host
  • Local access or remote access as an authenticated administrator
  • Windows Hyper-V role enabled on the target system
requires high privilegelocal or authenticated remote exploitationlow complexityaffects virtualization infrastructureno active exploitation reported
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul Microsoft security update to all Windows 10, Windows 11, and Windows Server systems running Hyper-V
API: /api/v1/advisories/a2d76d13-5e7a-4323-828e-82dcf0bdeca1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Hyper-V Elevation of Privilege Vulnerability | CVSS 8.2 - OTPulse