ZeroHour

CVE-2026-80083

mass

Untrusted Pointer Dereference in Windows Hyper-V Allows Local Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-80083 is an untrusted pointer dereference (CWE-822) in Windows Hyper-V that Microsoft rates 8.8 (High). It is triggered by an authorized, low-privileged attacker acting locally without user interaction, and the CVSS scope-changed metric indicates the impact extends beyond the vulnerable component's security boundary — for a hypervisor, typically meaning code execution on the host triggered from within a guest VM. Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability. Any Windows host with the Hyper-V role or feature enabled is potentially affected (the affected editions and update details are listed in Microsoft's advisory), with the greatest risk in environments where untrusted users can sign in to guest VMs. There is no known public PoC, the issue is not in CISA KEV, and a 0.2% EPSS suggests low near-term exploitation probability.

What to do: Check Microsoft's advisory for the affected Windows editions and apply the released security update, prioritizing Hyper-V hosts that run untrusted or third-party VMs. Until patched, restrict which users can sign in to or create guest VMs on shared hosts, since a low-privileged local/guest account is sufficient to trigger the flaw. Monitor the dashboard for KEV additions or public PoCs given the current none-known exploitation status.

Affected
Microsoft Windows Hyper-V
Estimated exposure
mass≈ millions of Windows hosts with the Hyper-V role/feature enabled — Hyper-V is a built-in role/feature across Windows Server and Windows Pro/Enterprise client editions and is one of the most widely deployed enterprise hypervisors, implying an install base plausibly exceeding one million hosts; exact counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.