CVE-2026-69553
massMissing Authorization Flaw in Windows Hyper-V Enables Network Privilege Escalation
CVE-2026-69553 is a missing authorization check (CWE-862) in Windows Hyper-V that fails to properly validate permissions on a network-accessible operation. Per the CVSS vector (AV:N/AC:H/PR:L/UI:R), exploitation requires an attacker who already holds low-privileged, authorized access to reach the host over the network, and also involves high attack complexity and some form of user interaction. Successful exploitation yields elevation of privileges with high impact to confidentiality, integrity, and availability, scoped to the affected component. Any organization running Windows with the Hyper-V role or feature enabled is in scope; the provided data does not specify affected version ranges, so defenders should consult Microsoft's advisory for exact affected builds. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.5% probability of exploitation within 30 days (41st percentile).
What to do: Inventory your Windows Server and Windows client fleets for systems where the Hyper-V role/feature is enabled, and apply the security update referenced in Microsoft's advisory once available, since this dataset does not list specific fixed builds or KB numbers. In the interim, restrict network access to Hyper-V hosts and their management interfaces so that only trusted, authorized users can reach them, which limits the PR:L/UI:R attack path. With no known exploitation, no public PoC, and EPSS at 0.5%, routine patch-cycle prioritization is defensible, but consider accelerating for multi-tenant or externally reachable virtualization hosts.
| Microsoft Windows Hyper-V | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.