CVE-2026-69603
massHeap buffer overflow in Windows Hyper-V enables local code execution
CVE-2026-69603 is a heap-based buffer overflow (CWE-122) in Windows Hyper-V that an authorized, low-privileged local attacker can trigger without user interaction to execute code. The changed-scope metric in the CVSS vector (S:C) indicates exploitation crosses a security boundary beyond the calling process, plausibly from a guest VM to the host, although the available data does not specify the vulnerable component or the exact boundary crossed. Successful exploitation carries high impact on confidentiality, integrity, and availability. Any Windows host with Hyper-V deployed, including server virtualization hosts and Windows client systems with the feature enabled, is affected; specific version ranges are not provided in the available data. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.
What to do: Install the Microsoft Windows security update that addresses CVE-2026-69603 for your affected Windows versions and confirm the exact affected ranges in Microsoft's advisory. Until patched, limit untrusted local accounts on Hyper-V hosts and restrict who can run workloads inside guest VMs on shared servers. Prioritize virtualization hosts that accept logins from many users, because exploitation requires only low privileges and no user interaction.
| Microsoft Windows Hyper-V (hosts with the Hyper-V role/feature enabled) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.