CVE-2026-25170
vulnerability analysis and mitigation

Overview

CVE-2026-25170 is a use-after-free (UAF) elevation of privilege vulnerability in Windows Hyper-V that allows an authorized attacker to escalate privileges locally. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Windows 11 (versions 23H2, 24H2, 25H2, and 26H1) and Windows Server 2022 and 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within the Windows Hyper-V hypervisor component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the contents of that memory and redirect execution flow. Exploitation requires local access with low privileges, and the attack complexity is rated High, indicating that specific conditions or race conditions must be met to trigger the flaw. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).

Impact

Successful exploitation allows an authenticated attacker with low privileges to escalate to SYSTEM-level access on the affected host, resulting in high impact to confidentiality, integrity, and availability. This could enable an attacker to fully compromise the host operating system, access sensitive data, tamper with system configurations, or disrupt services. In virtualized environments, privilege escalation on a Hyper-V host could have broader implications for all hosted virtual machines (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on March 10, 2026, addressing all affected versions. Administrators should apply the following updates: Windows 11 23H2 → build 10.0.22631.6783 or later; Windows 11 24H2 → build 10.0.26100.7979 or later; Windows 11 25H2 → build 10.0.26200.7979 or later; Windows 11 26H1 → build 10.0.28000.1719 or later; Windows Server 2022 → build 10.0.20348.4830 or later; Windows Server 2022 23H2 → build 10.0.25398.2207 or later; Windows Server 2025 → build 10.0.26100.32463 or later. As interim measures, restrict local user access, enforce the principle of least privilege, and monitor Hyper-V activity for anomalies (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, Zero Day Initiative, and SANS ISC, which collectively noted the patch addressed 79 vulnerabilities including two zero-days (unrelated to this CVE). Community coverage was routine, with no specific alarm raised about CVE-2026-25170 given the absence of public exploits and its High (rather than Critical) severity rating (Rapid7 Blog, Sophos Blog, ZDI Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management