CVE-2026-72961 – Windows Hyper-V Elevation of Privilege Vulnerability

CVSS 8.2 IMPORTANT Critical - Same Day Deployment

“A compromised Hyper-V administrator could turn crafted virtual TPM data into higher privileges, crossing an important security boundary.”

CVE-2026-72961 is a Critical Windows Hyper-V elevation-of-privilege vulnerability. An authorized attacker with administrative access to an affected Hyper-V host can supply specially crafted virtual TPM state data to a virtual machine. Successful exploitation can cross a security boundary and grant Virtual Trust Level 1 (VTL1) privileges. The vulnerability requires local access and high privileges but does not require user interaction.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.