PatchSiren cyber security CVE debrief
CVE-2026-50485 Microsoft CVE debrief
A buffer over-read vulnerability exists in Windows Hyper-V that could allow an authorized local attacker to cause a denial of service via an adjacent network. The vulnerability has a CVSS score of 4.5 and a severity rating of MEDIUM. Microsoft has released a patch for this vulnerability. This vulnerability affects Windows Hyper-V systems, and system administrators should review and update system configurations to ensure Hyper-V is properly secured. The vulnerability is a buffer over-read issue in Windows Hyper-V, and an authorized local attacker could exploit this vulnerability to cause a denial of service via an adjacent network.
- Vendor
- Microsoft
- Product
- Windows 10 Version 1607
- CVSS
- MEDIUM 4.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-21
Who should care
System administrators and security teams responsible for Windows Hyper-V systems should be aware of this vulnerability and take steps to mitigate it. They should review and update system configurations to ensure Hyper-V is properly secured and monitor system logs for potential exploitation attempts.
Technical summary
The vulnerability is a buffer over-read issue in Windows Hyper-V. An authorized local attacker could exploit this vulnerability to cause a denial of service via an adjacent network. The CVSS vector for this vulnerability is CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. This vulnerability affects Windows Hyper-V systems, and system administrators should review and update system configurations to ensure Hyper-V is properly secured.
Defensive priority
Medium priority
Recommended defensive actions
- Apply the patch released by Microsoft
- Review and update system configurations to ensure Hyper-V is properly secured
- Monitor system logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T18:17:54.560Z and was last modified on 2026-07-21T18:22:37.117Z. The NVD entry is currently Analyzed. This vulnerability affects Windows Hyper-V systems, and an authorized local attacker could exploit it to cause a denial of service via an adjacent network. The CVSS vector for this vulnerability is CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The vulnerability has a CVSS score of 4.5 and a severity rating of MEDIUM. Microsoft has released a patch for this vulnerability. Evidence limits suggest that additional information may be available from Microsoft or other sources, but it has not been verified.
Official resources
-
CVE-2026-50485 CVE record
CVE.org
-
CVE-2026-50485 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:54.560Z and has not been modified since then. The NVD entry is currently Analyzed.