CVE-2026-83501 – Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability

CVSS 5.5 MODERATE Critical - Same Day Deployment

“This VBS flaw can expose higher-trust data to a lower-trust environment, weakening one of Windows’ key isolation boundaries.”

CVE-2026-83501 is an information disclosure vulnerability in Windows Virtualization-Based Security (VBS) Enclave caused by an out-of-bounds read. An authorized local attacker with low privileges could exploit the flaw without user interaction and potentially view Virtual Trust Level 1 (VTL1) data from Virtual Trust Level 0 (VTL0), the least privileged trust level.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-125
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.