
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21248 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authorized local attacker to execute arbitrary code. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.3 (High) (Microsoft MSRC).
The vulnerability is rooted in a heap-based buffer overflow (CWE-122) combined with an out-of-bounds write (CWE-787) within the Windows Hyper-V hypervisor component. An attacker with low privileges on a local system can trigger the overflow through crafted operations, leading to arbitrary code execution. Exploitation requires user interaction and local access, meaning the attacker must already have an authenticated session on the target system. A public exploit was later published on Exploit-DB (entry 52537) (Microsoft MSRC, Exploit-DB).
Successful exploitation grants an attacker the ability to execute arbitrary code locally on the affected Hyper-V host, resulting in high confidentiality, integrity, and availability impacts. Because Hyper-V hosts manage virtual machines, a compromised host could allow an attacker to control all guest VMs running on that system, enabling significant lateral movement within virtualized environments. The scope of impact is rated as unchanged, meaning the exploit does not inherently break out of the Hyper-V security boundary on its own, but full host compromise is a realistic outcome (Microsoft MSRC).
vmwp.exe, vmms.exe) such as cmd.exe, powershell.exe, or network tools.Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected platforms. Key patched version thresholds include: Windows 11 24H2/25H2 at build 10.0.26100.7781 / 10.0.26200.7781, Windows 11 23H2 at 10.0.22631.6649, Windows Server 2025 at 10.0.26100.32313, Windows Server 2022 at 10.0.20348.4711, Windows Server 2022 23H2 at 10.0.25398.2149, Windows Server 2019/Windows 10 1809 at 10.0.17763.8389, Windows Server 2016/Windows 10 1607 at 10.0.14393.8868, Windows 10 21H2 at 10.0.19044.6937, and Windows 10 22H2 at 10.0.19045.6937. As interim mitigations, organizations should restrict local access to Hyper-V hosts, enforce least-privilege principles, and monitor for suspicious local activity on virtualization infrastructure (Microsoft MSRC).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by multiple security vendors. Rapid7, Qualys, Cisco Talos, Sophos, and BleepingComputer all included it in their Patch Tuesday analyses, noting it as a notable Hyper-V flaw requiring prompt patching. The Qualys May 2026 Patch Tuesday review also referenced the CVE in the context of ongoing patch prioritization. No specific high-profile researcher commentary or significant social media controversy was identified beyond standard Patch Tuesday coverage (Rapid7, Qualys Blog, BleepingComputer, Talos Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."