CVE-2025-48822

8.6

Microsoft · Windows Hyper-V

An out-of-bounds read vulnerability in Windows Hyper-V allows a local attacker to execute arbitrary code.

Executive summary

A critical out-of-bounds read vulnerability in Windows Hyper-V permits local attackers to execute code, posing a significant risk to host system integrity.

Vulnerability

This is an out-of-bounds read flaw (CWE-125) within the Windows Hyper-V hypervisor, which can be triggered by an unauthorized local attacker to achieve code execution. The attack vector is local, requiring the attacker to already possess the ability to execute code on the system.

Business impact

The potential for unauthorized code execution within the hypervisor layer represents a severe security risk, as it may allow an attacker to escape the virtual machine boundary or compromise the host operating system. Given the CVSS score of 8.6, this vulnerability is classified as High severity, necessitating prioritized remediation to prevent full system compromise and unauthorized data access.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide to all affected Windows host systems.

Proactive Monitoring: Monitor system logs for unusual Hyper-V service activity or unauthorized attempts to access hypervisor-managed resources.

Compensating Controls: Ensure that access to the host environment is strictly restricted to authorized personnel and utilize endpoint detection and response tools to identify anomalous local execution patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should treat this vulnerability with high urgency despite the requirement for local access. System administrators must prioritize the deployment of Microsoft security updates to the affected Windows versions to mitigate the risk of host-level code execution and potential hypervisor escape.

More Microsoft CVEs

Sources