CVE-2026-21248
vulnerability analysis and mitigation

Overview

CVE-2026-21248 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authorized local attacker to execute arbitrary code. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.3 (High) (Microsoft MSRC).

Technical details

The vulnerability is rooted in a heap-based buffer overflow (CWE-122) combined with an out-of-bounds write (CWE-787) within the Windows Hyper-V hypervisor component. An attacker with low privileges on a local system can trigger the overflow through crafted operations, leading to arbitrary code execution. Exploitation requires user interaction and local access, meaning the attacker must already have an authenticated session on the target system. A public exploit was later published on Exploit-DB (entry 52537) (Microsoft MSRC, Exploit-DB).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code locally on the affected Hyper-V host, resulting in high confidentiality, integrity, and availability impacts. Because Hyper-V hosts manage virtual machines, a compromised host could allow an attacker to control all guest VMs running on that system, enabling significant lateral movement within virtualized environments. The scope of impact is rated as unchanged, meaning the exploit does not inherently break out of the Hyper-V security boundary on its own, but full host compromise is a realistic outcome (Microsoft MSRC).

Exploitation steps

  1. Gain Local Access: Obtain an authenticated low-privilege session on a Windows system with Hyper-V enabled (e.g., via phishing, credential theft, or insider access).
  2. Identify Target: Confirm the target is running a vulnerable version of Windows with Hyper-V active (e.g., Windows 11 24H2 below build 10.0.26100.7781 or Windows Server 2025 below 10.0.26100.32313).
  3. Trigger User Interaction: Craft a scenario requiring minimal user interaction (as specified by the CVSS vector) to initiate the vulnerable Hyper-V code path — this may involve opening a malicious file or triggering a specific Hyper-V operation.
  4. Exploit Heap Overflow: Deliver a crafted payload that causes an out-of-bounds write in the Hyper-V heap, corrupting adjacent memory structures to redirect code execution.
  5. Execute Arbitrary Code: Leverage the memory corruption to execute attacker-controlled code in the context of the Hyper-V process, achieving full host compromise and potential control over all hosted virtual machines (Exploit-DB, Microsoft MSRC).

Indicators of compromise

  • Process: Unexpected child processes spawned by Hyper-V-related processes (e.g., vmwp.exe, vmms.exe) such as cmd.exe, powershell.exe, or network tools.
  • Logs: Windows Event Log entries showing crashes or unexpected restarts of Hyper-V worker processes; Application event log errors related to memory access violations in Hyper-V components.
  • File System: Presence of the Exploit-DB exploit file (entry 52537) or related artifacts on disk; unexpected scripts or executables in Hyper-V host directories.
  • Network: Unusual outbound connections from the Hyper-V host to external IPs following local code execution, potentially indicating post-exploitation activity such as C2 communication.

Mitigation and workarounds

Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected platforms. Key patched version thresholds include: Windows 11 24H2/25H2 at build 10.0.26100.7781 / 10.0.26200.7781, Windows 11 23H2 at 10.0.22631.6649, Windows Server 2025 at 10.0.26100.32313, Windows Server 2022 at 10.0.20348.4711, Windows Server 2022 23H2 at 10.0.25398.2149, Windows Server 2019/Windows 10 1809 at 10.0.17763.8389, Windows Server 2016/Windows 10 1607 at 10.0.14393.8868, Windows 10 21H2 at 10.0.19044.6937, and Windows 10 22H2 at 10.0.19045.6937. As interim mitigations, organizations should restrict local access to Hyper-V hosts, enforce least-privilege principles, and monitor for suspicious local activity on virtualization infrastructure (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security vendors. Rapid7, Qualys, Cisco Talos, Sophos, and BleepingComputer all included it in their Patch Tuesday analyses, noting it as a notable Hyper-V flaw requiring prompt patching. The Qualys May 2026 Patch Tuesday review also referenced the CVE in the context of ongoing patch prioritization. No specific high-profile researcher commentary or significant social media controversy was identified beyond standard Patch Tuesday coverage (Rapid7, Qualys Blog, BleepingComputer, Talos Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management