Windows Hyper-V Elevation of Privilege Vulnerability
Plan PatchCVSS 7.4CVE-2026-54127Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows Hyper-V allows a local attacker to execute code with elevated (system) privileges. The vulnerability affects Windows Server 2022 and 2025, as well as Windows 11 systems with Hyper-V installed. Microsoft has released fixes in the July 2026 security update for all affected versions.
What this means
What could happen
An attacker with local access to a Windows Server or Windows 11 system running Hyper-V could execute code with elevated privileges, potentially compromising the entire host system and any virtual machines it runs.
Who's at risk
Windows Server 2022 and 2025 administrators and Windows 11 users, particularly those running Hyper-V for virtual machine hosting. This affects utilities using Windows-based virtualization for operational technology systems or desktop workstations.
How it could be exploited
An attacker with a user account on a Windows Server or Windows 11 system could exploit a use-after-free flaw in the Hyper-V kernel driver to execute arbitrary code with system-level privileges. This requires local system access but no special credentials or configuration.
Prerequisites
- Local user account on the affected Windows Server or Windows 11 system
- Hyper-V installed and enabled on the system
Local exploitation requiredLow EPSS score (0.3%)Vendor fix available for all affected versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (9)
9 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later via Windows Update
All products
HOTFIXUpdate Windows 11 to Build 10.0.26100.8875 or later (for versions 24H2 and 25H2) or Build 10.0.28000.2525 (for version 26H1) via Windows Update
Long-term hardening
0/2HARDENINGRestrict local system access to trusted users only; review and remove unnecessary local user accounts on Windows Server and Windows 11 systems
WORKAROUNDDisable Hyper-V on systems where it is not required for operations
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0055257a-daf6-448f-af80-41b9bc8cf93fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.