ZeroHour

CVE-2026-72961

mass

Out-of-Bounds Read Local Privilege Escalation in Windows Hyper-V

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72961 is an out-of-bounds read (CWE-122) in Windows Hyper-V, Microsoft's built-in hypervisor, assigned by Microsoft's CNA. The flaw is triggered locally by an authorized attacker on a system where Hyper-V is present; the CVSS vector (AV:L, PR:H, scope changed) indicates the attacker must already hold high local privileges and that the impact can cross the component's security scope. Successful exploitation allows the attacker to elevate privileges locally, with high confidentiality, integrity, and availability impact per the CVSS scoring. Any organization running Windows systems with the Hyper-V role or feature enabled is potentially affected. There is currently no known exploitation, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.3%); the vulnerability is not listed in CISA's KEV catalog.

What to do: Inventory hosts and endpoints with the Hyper-V role/feature enabled and prioritize them for Microsoft's security update once released; do not rely on version ranges beyond Microsoft's advisory, as affected builds are not yet specified in available data. Until patching, limit high-privileged local access on Hyper-V hosts and monitor Microsoft's advisory for updated affected-product and version details.

Affected
Microsoft Windows Hyper-V
Estimated exposure
mass≈ millions of hosts (Windows Server and Windows 10/11 Pro/Enterprise systems with Hyper-V enabled) — Hyper-V is a built-in role in Windows Server and an optional feature in Windows Pro/Enterprise editions (and underlies features like WSL2 and Windows Sandbox), implying an installed base in the millions, though only systems with Hyper-V…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.