Windows Hyper-V
by Microsoft
CVEs (89)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41094 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2022-24537 | Hig | 0.51 | 7.8 | 0.00 | Apr 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2021-28314 | Hig | 0.51 | 7.8 | 0.01 | Apr 13, 2021 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2020-1047 | Hig | 0.51 | 7.8 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system. This vulnerability… | ||
| CVE-2017-0193 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2017 | Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating… | ||
| CVE-2019-0709 | Hig | 0.50 | 7.6 | 0.04 | Jun 12, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating… | ||
| CVE-2019-0620 | Hig | 0.50 | 7.6 | 0.01 | Jun 12, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating… | ||
| CVE-2017-0212 | Hig | 0.49 | 7.6 | 0.01 | May 12, 2017 | Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability". | ||
| CVE-2026-32149 | Hig | 0.47 | 7.3 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2026-21247 | Hig | 0.47 | 7.3 | 0.01 | Feb 10, 2026 | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2026-69553 | Hig | 0.46 | 7.1 | 0.01 | Sep 8, 2026 | Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-25170 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54115 | Hig | 0.46 | 7.0 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50167 | Hig | 0.46 | 7.0 | 0.00 | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27491 | Hig | 0.46 | 7.1 | 0.02 | Apr 8, 2025 | Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. | ||
| CVE-2024-20659 | Hig | 0.46 | 7.1 | 0.01 | Oct 8, 2024 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2025-49751 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2025-48807 | Med | 0.44 | 6.7 | 0.00 | Aug 12, 2025 | Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2025-47999 | Med | 0.44 | 6.8 | 0.00 | Jul 8, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2022-44682 | Med | 0.44 | 6.8 | 0.01 | Dec 13, 2022 | Windows Hyper-V Denial of Service Vulnerability |
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system. This vulnerability…
- risk 0.51cvss 7.8epss 0.02
Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating…
- risk 0.50cvss 7.6epss 0.04
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating…
- risk 0.50cvss 7.6epss 0.01
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating…
- risk 0.49cvss 7.6epss 0.01
Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability".
- risk 0.47cvss 7.3epss 0.00
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.47cvss 7.3epss 0.01
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.01
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.02
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.1epss 0.01
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.00
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.44cvss 6.7epss 0.00
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.8epss 0.00
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.44cvss 6.8epss 0.01
Windows Hyper-V Denial of Service Vulnerability
Page 3 of 5