ZeroHour

CVE-2026-69603

mass

Heap buffer overflow in Windows Hyper-V enables local code execution

CVSS 3.1
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-69603 is a heap-based buffer overflow (CWE-122) in Windows Hyper-V that an authorized, low-privileged local attacker can trigger without user interaction to execute code. The changed-scope metric in the CVSS vector (S:C) indicates exploitation crosses a security boundary beyond the calling process, plausibly from a guest VM to the host, although the available data does not specify the vulnerable component or the exact boundary crossed. Successful exploitation carries high impact on confidentiality, integrity, and availability. Any Windows host with Hyper-V deployed, including server virtualization hosts and Windows client systems with the feature enabled, is affected; specific version ranges are not provided in the available data. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Install the Microsoft Windows security update that addresses CVE-2026-69603 for your affected Windows versions and confirm the exact affected ranges in Microsoft's advisory. Until patched, limit untrusted local accounts on Hyper-V hosts and restrict who can run workloads inside guest VMs on shared servers. Prioritize virtualization hosts that accept logins from many users, because exploitation requires only low privileges and no user interaction.

Affected
Microsoft Windows Hyper-V (hosts with the Hyper-V role/feature enabled)
Estimated exposure
massmillions of Windows hosts (Hyper-V ships in Windows Server and Windows client editions and is widely deployed) — Hyper-V is built into Windows Server and Windows client editions and is commonly enabled in server virtualization fleets and on client machines used for virtualization workloads, so the installed base of potentially affected hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.