CVE-2026-21248
HIGHWindows 10/11, Server 2016/2019/2022 Hyper-V Authenticated Heap-based Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-21248. PoCs published by nu11secur1ty.
AI-analyzed exploit summary This exploit demonstrates a heap-based buffer overflow in Windows Hyper-V VMBus GPADL allocation (CVE-2026-21248) by generating a malicious .vhdx file with a crafted BAT entry. It requires local access and Hyper-V Administrator privileges, contradicting Microsoft's initial CVSS assessment of no privileges required.
Description
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Exploits (1)
This exploit demonstrates a heap-based buffer overflow in Windows Hyper-V VMBus GPADL allocation (CVE-2026-21248) by generating a malicious .vhdx file with a crafted BAT entry. It requires local access and Hyper-V Administrator privileges, contradicting Microsoft's initial CVSS assessment of no privileges required.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H