Windows Hyper-V Information Disclosure Vulnerability
MonitorCVSS 5CVE-2026-61368Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
What this means
What could happen
An attacker with local access and user-level credentials on a Windows system running Hyper-V could extract sensitive information from system memory, potentially exposing configuration details or data from running virtual machines.
Who's at risk
IT managers running Windows Server 2016, 2019, 2022, or 2025 with Hyper-V enabled for virtualization. Also affects Windows 10 and Windows 11 systems with Hyper-V role installed. This impacts any organization using Hyper-V for virtual machine hosting or testing environments.
How it could be exploited
An attacker must first gain local user-level access to a Windows system where Hyper-V is enabled. They then exploit a heap buffer overflow in the Hyper-V service to read sensitive information from memory. This requires local interactive access and is not remotely exploitable.
Prerequisites
- Local user-level credentials on the Windows system
- Hyper-V role or feature must be installed and running on the target system
- User interaction or ability to interact with the Hyper-V service
requires local credentialsrequires user interactionaffects Hyper-V hostsheap buffer overflowlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXInstall Windows security update from August 2026 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/252c6bfc-9cac-40f1-8f4d-785c38042014Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.