CVE-2026-50485
Analyzed Analyzed - Analysis Complete

Buffer Over-Read in Windows Hyper-V

Vulnerability report for CVE-2026-50485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-21

Assigner: Microsoft Corporation

Description

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-21
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50485 is a buffer over-read vulnerability in Windows Hyper-V. This flaw occurs when the software reads more data from a buffer than is allocated, which can lead to unintended behavior.

An authorized attacker with high privileges (PR:H) can exploit this vulnerability over an adjacent network (AV:A). The attack does not require user interaction (UI:N) and can result in a denial of service (A:H), meaning it can crash or disrupt the affected Hyper-V service.

Detection Guidance

Detection requires monitoring Hyper-V network traffic for abnormal patterns or crashes. Check Windows Event Logs for Hyper-V-related errors or service disruptions. Use network monitoring tools to inspect adjacent network segments for unusual traffic targeting Hyper-V hosts.

Impact Analysis

If you are using Windows Hyper-V, this vulnerability could impact you in the following ways:

  • Denial of Service (DoS): An attacker with authorized access to an adjacent network could exploit this flaw to crash or disrupt the Hyper-V service, leading to downtime for virtual machines or hosted services.
  • Limited Scope: The attack requires adjacent network access and high privileges, reducing the risk of widespread exploitation but still posing a threat in shared or multi-tenant environments.

No data theft or code execution is indicated, so the primary risk is service disruption.

Compliance Impact

This vulnerability may impact compliance with standards and regulations in the following ways:

  • GDPR: If the affected Hyper-V environment processes personal data of EU citizens, a denial of service could lead to availability issues, potentially violating GDPR's requirements for data availability and resilience (Article 32).
  • HIPAA: For healthcare organizations, service disruption in Hyper-V could affect the availability of protected health information (PHI), potentially violating HIPAA's Security Rule, which mandates safeguards for electronic PHI.
  • Other Standards: Compliance frameworks like ISO 27001 or NIST SP 800-53 emphasize system availability and resilience. A DoS vulnerability could indicate a failure to meet these requirements.

However, the specific impact depends on the environment and how critical Hyper-V is to your operations. Patching the vulnerability promptly would help maintain compliance.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-50485. The update can be found on the Microsoft Update Guide for this vulnerability.

Ensure that only authorized users have access to the Hyper-V environment, as the vulnerability requires an authorized attacker.

Monitor adjacent networks for unusual activity that could indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart