CVE-2026-21255
8.8Microsoft · Windows Hyper-V
An improper access control vulnerability in Windows Hyper-V allows a locally authenticated attacker to bypass security features and potentially achieve full system compromise.
Executive summary
A critical access control flaw in Microsoft Windows Hyper-V allows an authenticated local attacker to bypass security features, posing a high risk of total system compromise.
Vulnerability
The vulnerability is identified as an improper access control issue (CWE-284) within the Windows Hyper-V component. It requires an authenticated user with local access to the system to exploit the flaw, bypassing established security boundaries.
Business impact
The exploitation of this vulnerability could lead to a complete loss of confidentiality, integrity, and availability of the affected host system. Given the CVSS score of 8.8, this is a high-severity issue that could allow an attacker to escalate privileges or move laterally from a compromised user account to the hypervisor level. This poses significant risks to organizational data security and infrastructure stability.
Remediation
Immediate Action: Apply the relevant Microsoft security updates corresponding to your specific Windows version and build number as detailed in the MSRC update guide.
Proactive Monitoring: Monitor local system access logs for unauthorized attempts to interact with Hyper-V management interfaces or unexpected privilege escalation events.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local users, limiting the number of accounts that have the ability to interact with virtualization services.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should treat this vulnerability with high priority due to the potential for hypervisor-level compromise. IT administrators must verify their current Windows build versions against the provided list and apply the necessary patches provided by Microsoft to eliminate this local attack vector.
More Microsoft CVEs
Sources
- Windows Hyper-V Security Feature Bypass Vulnerability Vendor advisory