CVE-2025-62567
vulnerability analysis and mitigation

Overview

CVE-2025-62567 is an integer underflow (wrap or wraparound) vulnerability in Windows Hyper-V that allows an authorized, low-privileged attacker to trigger a denial of service condition over a network. It was disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security updates. Affected products span a wide range of Windows versions including Windows 10 (21H2, 22H2, 1607, 1809), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012 R2, 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (MSRC).

Technical details

The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), occurring within Windows Hyper-V's memory management subsystem. When an authorized attacker sends specially crafted network input, an integer value can wrap around to an unexpected large value, potentially causing the hypervisor to enter an unstable or faulted state. Exploitation requires network access, low privileges, no user interaction, and high attack complexity, meaning the attacker must meet specific preconditions or timing requirements to reliably trigger the condition (MSRC). No public proof-of-concept or detailed technical write-up has been identified at this time.

Impact

Successful exploitation results in a denial of service (DoS) condition affecting the Windows Hyper-V hypervisor, with high availability impact and no confidentiality or integrity impact. This could cause system instability, service interruption, or temporary unavailability of virtualized workloads and guest virtual machines hosted on the affected Hyper-V host. The scope is unchanged, meaning the impact is confined to the vulnerable component itself and does not directly enable lateral movement or data exfiltration (MSRC).

Mitigation and workarounds

Microsoft released patches for CVE-2025-62567 as part of the December 2025 Patch Tuesday update (December 9, 2025). Administrators should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 11 24H2/Server 2025 → 10.0.26100.7392 (or 7462 per ENISA data), Windows 11 25H2 → 10.0.26200.7392, Windows 11 23H2 → 10.0.22631.6345, Windows Server 2022 → 10.0.20348.4467, Windows Server 2022 23H2 → 10.0.25398.2025, Windows Server 2019/Windows 10 1809 → 10.0.17763.8146, Windows Server 2016/Windows 10 1607 → 10.0.14393.8688, Windows 10 21H2 → 10.0.19044.6691, Windows 10 22H2 → 10.0.19045.6691, Windows Server 2012 R2 → 6.3.9600.22920. As interim mitigations, restrict network access to Hyper-V management interfaces, implement network segmentation to limit exposure, and monitor Hyper-V hosts for anomalous network activity (MSRC).

Community reactions

CVE-2025-62567 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with this vulnerability receiving standard coverage as a medium-severity DoS issue (Bleeping Computer). The Zero Day Initiative and Sophos also published Patch Tuesday review posts covering the December 2025 release (ZDI Blog, Sophos News). No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management