Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.4

Windows VBS Enclave Access Control Bypass

CVE-2026-32220
Summary

An authorized user on the same computer can bypass a security feature in Windows Virtualization-Based Security. This could allow a malicious user to access sensitive data or systems. Update your Windows system to the latest version to fix this vulnerability.

Original title
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
Original description
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd CVSS3.1 4.4
Vulnerability type
CWE-284 Improper Access Control
Published: 14 Apr 2026 · Updated: 15 Apr 2026 · First seen: 14 Apr 2026