ZDI-CAN-28769: ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28769?
The severity of ZDI-CAN-28769 is rated at 46 on the risk scale.
How do I fix ZDI-CAN-28769?
To fix ZDI-CAN-28769, you should apply the latest security updates provided by Microsoft for Hyper-V.
What types of systems are affected by ZDI-CAN-28769?
ZDI-CAN-28769 affects installations of Microsoft Hyper-V that can be exploited by local attackers.
What is the nature of the vulnerability in ZDI-CAN-28769?
ZDI-CAN-28769 is an out-of-bounds read vulnerability that allows local privilege escalation.
Can remote attackers exploit ZDI-CAN-28769?
No, ZDI-CAN-28769 requires an attacker to execute low-privileged code within a Windows virtual machine to exploit it.