CVE-2026-72961 – Windows Hyper-V Elevation of Privilege Vulnerability
CVSS 8.2
IMPORTANT
Critical - Same Day Deployment
“A compromised Hyper-V administrator could turn crafted virtual TPM data into higher privileges, crossing an important security boundary.”
CVE-2026-72961 is a Critical Windows Hyper-V elevation-of-privilege vulnerability. An authorized attacker with administrative access to an affected Hyper-V host can supply specially crafted virtual TPM state data to a virtual machine. Successful exploitation can cross a security boundary and grant Virtual Trust Level 1 (VTL1) privileges. The vulnerability requires local access and high privileges but does not require user interaction.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.