Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-69910

Опубликовано: 08 сент. 2026
Источник: msrc
CVSS3: 9.8
EPSS Низкий

Описание

Windows Hyper-V Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

FAQ

According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?

The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.

How could an attacker exploit this vulnerability?

This vulnerability would require an authenticated attacker on a guest VM to send specially crafted file operation requests on the VM to hardware resources on the VM which could result in remote code execution on the host server.

How could an attacker exploit this vulnerability?

By leveraging malicious TPM commands from a guest VM to a target running Hyper-V, an attacker can cause an out of bounds write in the root partition.

Обновления

ПродуктСтатьяОбновление
Windows Server 2016
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows Server 2016 (Server Core installation)
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for x64-based Systems
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 61%
0.00996
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
8 дней назад

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
github
8 дней назад

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

EPSS

Процентиль: 61%
0.00996
Низкий

9.8 Critical

CVSS3