Windows Hyper-V Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-54129Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free memory vulnerability exists in the Windows Hyper-V kernel driver. An authorized local user can exploit this to elevate privileges and gain SYSTEM-level access on the Hyper-V host. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker with a local user account on a Hyper-V host can exploit a memory issue to run code with system-level privileges, potentially allowing them to control virtual machines or the host itself.
Who's at risk
Organizations running Windows Server 2019, 2022, or 2025 with Hyper-V enabled should prioritize this patch. This affects IT infrastructure teams managing virtualized environments for operational data, remote access, or process monitoring. Windows 10 and Windows 11 systems with Hyper-V enabled in small IT environments are also impacted.
How it could be exploited
An attacker with a standard user account on a Windows system with Hyper-V installed can trigger a use-after-free condition in the Hyper-V kernel driver. By crafting specific requests or operations, they can execute arbitrary code with SYSTEM privileges, gaining full control of the host and all VMs running on it.
Prerequisites
- Local user account on a Windows system with Hyper-V role enabled
- Local code execution capability to trigger the vulnerable Hyper-V kernel code path
Low attack complexityRequires local authentication (insider threat)Affects virtualization hypervisorNo currently known public exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/9
Schedule — requires maintenance window
0/8Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit or x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.8875 or later
Long-term hardening
0/1HARDENINGRestrict local logon privileges to Hyper-V hosts; disable unnecessary local user accounts and enforce strong password policies
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9d175c7a-79a4-4ee3-8f4f-2692ab43b423Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.