Remote Code Execution Vulnerability in Windows Hyper-V by Microsoft
CVE-2025-48807

7.5HIGH

What is CVE-2025-48807?

An improper restriction of communication channels to intended endpoints in Windows Hyper-V allows an authorized attacker to execute arbitrary code locally. This vulnerability could potentially enable an attacker to gain access to protected systems and data, making it crucial to apply necessary security patches and updates to mitigate risks associated with this flaw.

Affected Version(s)

Windows 10 Version 1607 x64-based Systems 10.0.14393.0 < 10.0.14393.8246

Windows 10 Version 1809 x64-based Systems 10.0.17763.0 < 10.0.17763.7558

Windows 10 Version 21H2 x64-based Systems 10.0.19044.0 < 10.0.19044.6093

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48807 : Remote Code Execution Vulnerability in Windows Hyper-V by Microsoft