CVE-2026-40402

EUVD-2026-29663
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 CRITICAL
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_11_23h2
𝑥
< 10.0.22631.7079
microsoftwindows_11_23h2
𝑥
< 10.0.22631.7079
microsoftwindows_server_2022
𝑥
< 10.0.20348.5074
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 11
23H2 (arm64)
23H2 (x64)
Windows Server 2022
Server Core
Standard