ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-416?
The severity of ZDI-26-416 is rated at 49 on the CVSS scale.
How do I fix ZDI-26-416?
To mitigate ZDI-26-416, ensure that your Microsoft Hyper-V installations are updated with the latest security patches.
What type of vulnerability is ZDI-26-416?
ZDI-26-416 is classified as an Out-Of-Bounds Read Local Privilege Escalation Vulnerability.
Who can exploit ZDI-26-416?
ZDI-26-416 can be exploited by local attackers who have the ability to run low-privileged code within a Windows virtual machine.
Which software is affected by ZDI-26-416?
ZDI-26-416 affects Microsoft Hyper-V installations.