Windows Hyper-V Elevation of Privilege Vulnerability
Plan PatchCVSS 7.1CVE-2026-69553Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
A missing authorization check in Windows Hyper-V allows an authorized user to elevate privileges over the network. The vulnerability requires the attacker to have valid Windows credentials and user interaction but could allow full control of the Hyper-V host and any virtual machines it runs. Exploitation is considered less likely in the wild.
What this means
What could happen
A user with valid credentials on a Windows system running Hyper-V could gain administrative access to the host or virtual machines, potentially allowing them to take control of critical infrastructure servers or hypervisors that manage your OT environment.
Who's at risk
Organizations running Windows Server as hypervisors in their OT infrastructure, particularly those managing virtual PLCs, HMIs, or other control system components. Affected systems include Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025.
How it could be exploited
An attacker with valid Windows credentials performs an action through the network that exploits a missing authorization check in Hyper-V, gaining elevated privileges without requiring administrative approval. If your OT network uses Windows servers as hypervisors or management hosts, this could give an attacker control over virtual machines running control systems.
Prerequisites
- Valid Windows user credentials on the affected system
- Network access to the Hyper-V host
- User account must be on the same domain or have network reachability to the host
remotely exploitablerequires valid credentialsaffects virtualization hostsmoderate complexity attack
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the 2026-Sep Windows security update to all affected Windows 10, Windows 11, Windows Server 2019, Server 2022, and Server 2025 systems
Long-term hardening
0/2HARDENINGRestrict Hyper-V management access to trusted administrative networks using firewall rules or network segmentation
HARDENINGReview and limit user account privileges on Hyper-V hosts to only those who require management access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/98b95e6c-ca4e-4046-99f7-20ff3c8a8cb9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.