CVE-2026-21244
vulnerability analysis and mitigation

Overview

CVE-2026-21244 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authorized attacker with low privileges to execute arbitrary code locally. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022 (including 23H2), and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), and is associated with CAPEC-92 (Forced Integer Overflow). An authorized local attacker with low privileges can trigger an out-of-bounds write operation in the Windows Hyper-V component, leading to arbitrary code execution. Exploitation requires user interaction (UI:R) and operates within an unchanged scope, meaning the impact is confined to the vulnerable component. An exploit was published to Exploit-DB (entry 52537) in May 2026, indicating public availability of exploitation code (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability on the affected system. An attacker who exploits this vulnerability can execute arbitrary code within the context of the Hyper-V environment, potentially compromising guest or host system security, accessing sensitive data, and disrupting virtualized workloads. Given Hyper-V's role in server virtualization infrastructure, exploitation could have cascading effects across virtual machines hosted on the affected system (Microsoft MSRC).

Exploitation steps

  1. Gain local access: Obtain a low-privileged local account on a Windows system running Hyper-V (e.g., via phishing, credential theft, or insider access).
  2. Identify target: Confirm the target system is running an unpatched version of Windows with Hyper-V enabled (e.g., Windows Server 2022 prior to build 10.0.20348.4711, or Windows 11 24H2 prior to 10.0.26100.7781).
  3. Trigger user interaction: Craft or deliver a malicious input or action that requires the victim user to interact (e.g., opening a specially crafted file or triggering a specific Hyper-V operation), satisfying the UI:R requirement.
  4. Trigger heap overflow: Exploit the out-of-bounds write vulnerability in the Hyper-V component by supplying malformed data that overflows a heap buffer, corrupting adjacent memory structures.
  5. Achieve code execution: Leverage the memory corruption to redirect execution flow and run arbitrary code in the context of the Hyper-V process, potentially enabling privilege escalation or lateral movement within the virtualized environment (Microsoft MSRC, Exploit-DB).

Indicators of compromise

  • Process: Unexpected child processes spawned by Hyper-V-related processes (e.g., vmwp.exe, vmms.exe); unusual process creation events associated with low-privileged user accounts on Hyper-V hosts.
  • Logs: Windows Event Log entries (Event ID 1000/1001) indicating application crashes or faults in Hyper-V components; unexpected privilege escalation events in Security logs.
  • File System: Presence of exploit files (e.g., those matching Exploit-DB entry 52537) on the local filesystem; newly created or modified files in Hyper-V-related directories by non-administrative accounts.
  • Network: Unusual outbound connections from Hyper-V host processes to external IPs following local exploitation, potentially indicating post-exploitation activity such as C2 communication.

Mitigation and workarounds

Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Administrators should update to the following minimum build versions: Windows 10 1607 (10.0.14393.8868), Windows 10 1809/Windows Server 2019 (10.0.17763.8389), Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). As interim mitigations, restrict local access to Hyper-V hosts, enforce the principle of least privilege, and monitor for suspicious activity on virtualization infrastructure (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security vendors and researchers. Qualys, Rapid7, Talos Intelligence, Sophos, and BleepingComputer all included CVE-2026-21244 in their Patch Tuesday analyses, noting it as one of 58 vulnerabilities addressed that month. Coverage generally characterized it as a notable but not immediately critical issue given the local attack vector and user interaction requirement, with patching recommended as a priority for Hyper-V environments (Qualys Blog, Rapid7 Blog, Talos Blog, BleepingComputer).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management