CVE-2025-54091

7.8

Microsoft · Windows

An integer overflow or wraparound vulnerability in Windows Hyper-V allows a locally authenticated attacker to achieve privilege escalation.

Executive summary

A vulnerability in the Windows Hyper-V component allows a locally authenticated attacker to gain elevated system privileges, posing a significant risk to host integrity.

Vulnerability

This flaw involves an integer overflow or wraparound condition within the Hyper-V hypervisor. The vulnerability requires the attacker to possess local, authenticated access to the target system to trigger the flaw and achieve privilege escalation.

Business impact

Successful exploitation of this vulnerability allows an attacker with low-level local access to elevate their privileges, potentially gaining full control over the host operating system. Given the CVSS score of 7.8, this constitutes a High severity risk that could lead to complete system compromise, unauthorized data access, and the bypass of security boundaries between virtualized environments and the host.

Remediation

Immediate Action: Apply the September 2025 security updates provided by Microsoft via the official update guide to address the vulnerable Hyper-V components.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected administrative activities originating from non-privileged local user accounts.

Compensating Controls: Ensure that access to the local system is restricted to authorized personnel only, as the attack vector requires a local presence on the host machine.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the vendor-supplied security patches to all affected Windows hosts running the Hyper-V role. Because this vulnerability allows for privilege escalation, it serves as a critical link in an attack chain for adversaries already present within the environment; therefore, timely remediation is essential to maintain host security and prevent lateral movement or total system takeover.

More Microsoft CVEs

Sources