CVE-2026-72961
massOut-of-Bounds Read Local Privilege Escalation in Windows Hyper-V
CVE-2026-72961 is an out-of-bounds read (CWE-122) in Windows Hyper-V, Microsoft's built-in hypervisor, assigned by Microsoft's CNA. The flaw is triggered locally by an authorized attacker on a system where Hyper-V is present; the CVSS vector (AV:L, PR:H, scope changed) indicates the attacker must already hold high local privileges and that the impact can cross the component's security scope. Successful exploitation allows the attacker to elevate privileges locally, with high confidentiality, integrity, and availability impact per the CVSS scoring. Any organization running Windows systems with the Hyper-V role or feature enabled is potentially affected. There is currently no known exploitation, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.3%); the vulnerability is not listed in CISA's KEV catalog.
What to do: Inventory hosts and endpoints with the Hyper-V role/feature enabled and prioritize them for Microsoft's security update once released; do not rely on version ranges beyond Microsoft's advisory, as affected builds are not yet specified in available data. Until patching, limit high-privileged local access on Hyper-V hosts and monitor Microsoft's advisory for updated affected-product and version details.
| Microsoft Windows Hyper-V | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.