Windows Hyper-V Elevation of Privilege Vulnerability

Plan PatchCVSS 7.4CVE-2026-54127Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Hyper-V allows a local attacker to execute code with elevated (system) privileges. The vulnerability affects Windows Server 2022 and 2025, as well as Windows 11 systems with Hyper-V installed. Microsoft has released fixes in the July 2026 security update for all affected versions.

What this means
What could happen
An attacker with local access to a Windows Server or Windows 11 system running Hyper-V could execute code with elevated privileges, potentially compromising the entire host system and any virtual machines it runs.
Who's at risk
Windows Server 2022 and 2025 administrators and Windows 11 users, particularly those running Hyper-V for virtual machine hosting. This affects utilities using Windows-based virtualization for operational technology systems or desktop workstations.
How it could be exploited
An attacker with a user account on a Windows Server or Windows 11 system could exploit a use-after-free flaw in the Hyper-V kernel driver to execute arbitrary code with system-level privileges. This requires local system access but no special credentials or configuration.
Prerequisites
  • Local user account on the affected Windows Server or Windows 11 system
  • Hyper-V installed and enabled on the system
Local exploitation requiredLow EPSS score (0.3%)Vendor fix available for all affected versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (9)
9 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later via Windows Update
All products
HOTFIXUpdate Windows 11 to Build 10.0.26100.8875 or later (for versions 24H2 and 25H2) or Build 10.0.28000.2525 (for version 26H1) via Windows Update
Long-term hardening
0/2
HARDENINGRestrict local system access to trusted users only; review and remove unnecessary local user accounts on Windows Server and Windows 11 systems
WORKAROUNDDisable Hyper-V on systems where it is not required for operations
API: /api/v1/advisories/0055257a-daf6-448f-af80-41b9bc8cf93f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Hyper-V Elevation of Privilege Vulnerability | CVSS 7.4 - OTPulse