CVE-2026-69603 – Windows Hyper-V Remote Code Execution Vulnerability
CVSS 8.8
IMPORTANT
Critical - Same Day Deployment
“A malicious hypercall can turn a memory flaw in Hyper-V into high-impact code execution across a security boundary.”
CVE-2026-69603 is a critical heap-based buffer overflow vulnerability in Windows Hyper-V. An authorized attacker running code inside a virtualized environment can issue a specially crafted hypercall containing a maliciously large or malformed payload size. This can trigger a buffer overflow in the hypervisor during memory operations and allow local code execution. The vulnerability requires low privileges and no user interaction.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.