CVE-2021-28476

CRITICAL

Windows Hyper-V - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2021-28476. PoCs published by 0vercl0k, bluefrostsecurity, dengyang123x.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-28476, a guest-to-host Hyper-V Remote Code Execution vulnerability in vmswitch.sys. The exploit leverages a malicious RNDIS packet sent over VMBus to trigger an arbitrary memory read in the host system.

Description

Windows Hyper-V Remote Code Execution Vulnerability

Exploits (6)

nomisec WORKING POC 226 stars
by 0vercl0k · poc
https://github.com/0vercl0k/CVE-2021-28476

This repository contains a functional proof-of-concept exploit for CVE-2021-28476, a guest-to-host Hyper-V Remote Code Execution vulnerability in vmswitch.sys. The exploit leverages a malicious RNDIS packet sent over VMBus to trigger an arbitrary memory read in the host system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Hyper-V (vmswitch.sys)
No auth needed
Prerequisites: A guest virtual machine running Linux with modified kernel modules · Access to Hyper-V host via VMBus
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP 10 stars
by bluefrostsecurity · poc
https://github.com/bluefrostsecurity/CVE-2021-28476

The repository describes multiple vulnerabilities in Microsoft Hyper-V's vmswitch component, specifically involving WPP code handling of set OID requests, leading to pointer dereference and out-of-bounds read issues. It references an external technical advisory for detailed analysis.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Hyper-V
No auth needed
Prerequisites: Access to Hyper-V environment · Ability to send crafted OID requests
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB 1 stars
by dengyang123x · poc
https://github.com/dengyang123x/0vercl0k

The repository contains only a minimal README with a brief description of CVE-2021-28476, a Hyper-V guest-to-host RCE vulnerability in vmswitch.sys, but no actual exploit code or technical details.

Classification
Stub 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Hyper-V (vmswitch.sys)
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by LaCeeKa · poc
https://github.com/LaCeeKa/CVE-2021-28476-tools-env

This repository contains a functional exploit PoC for CVE-2021-28476, targeting a vulnerability in the Hyper-V network driver. It includes modified kernel module source code and tools to compile, load, and execute the exploit.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Linux kernel Hyper-V network driver (hv_netvsc)
Auth required
Prerequisites: Root access for module loading · Hyper-V environment
devstral-2 · analyzed Feb 18, 2026 Full analysis →
gitlab WORKING POC
by securitystuffbackup · poc
https://gitlab.com/securitystuffbackup/CVE-2021-28476

This repository contains a functional proof-of-concept exploit for CVE-2021-28476, a guest-to-host Hyper-V Remote Code Execution vulnerability in vmswitch.sys. The exploit leverages a malicious RNDIS packet sent over VMBus to trigger an arbitrary memory read in the host system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Hyper-V (vmswitch.sys)
No auth needed
Prerequisites: Linux guest VM with modified Hyper-V network drivers · Access to Hyper-V host via VMBus
devstral-2 · analyzed Feb 23, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/australeo/cve-2021-28476

This repository contains a functional exploit PoC for CVE-2021-28476, which leverages an arbitrary pointer dereference vulnerability in Hyper-V's vmswitch.sys driver. The exploit triggers a DoS condition by sending a crafted OID request from a guest VM, causing the host kernel to crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Hyper-V (vmswitch.sys)
No auth needed
Prerequisites: Hyper-V guest VM with modified Linux Hyper-V driver
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.9
EPSS 0.5515
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (18)
microsoft/windows_10
microsoft/windows_10 20h2
microsoft/windows_10 1607
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_server_2008
... and 8 more
Published May 11, 2021
Tracked Since Feb 18, 2026