Windows Hyper-V Information Disclosure Vulnerability

MonitorCVSS 5CVE-2026-61368Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.

What this means
What could happen
An attacker with local access and user-level credentials on a Windows system running Hyper-V could extract sensitive information from system memory, potentially exposing configuration details or data from running virtual machines.
Who's at risk
IT managers running Windows Server 2016, 2019, 2022, or 2025 with Hyper-V enabled for virtualization. Also affects Windows 10 and Windows 11 systems with Hyper-V role installed. This impacts any organization using Hyper-V for virtual machine hosting or testing environments.
How it could be exploited
An attacker must first gain local user-level access to a Windows system where Hyper-V is enabled. They then exploit a heap buffer overflow in the Hyper-V service to read sensitive information from memory. This requires local interactive access and is not remotely exploitable.
Prerequisites
  • Local user-level credentials on the Windows system
  • Hyper-V role or feature must be installed and running on the target system
  • User interaction or ability to interact with the Hyper-V service
requires local credentialsrequires user interactionaffects Hyper-V hostsheap buffer overflowlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXInstall Windows security update from August 2026 or later
API: /api/v1/advisories/252c6bfc-9cac-40f1-8f4d-785c38042014

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Hyper-V Information Disclosure Vulnerability | CVSS 5 - OTPulse