Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-57092: Windows VMSwitch Privilege Elevation Over Network

CVE-2026-57092 CVE-2026-57092
Summary

An attacker with authorized access to Windows VMSwitch over a network can potentially gain elevated privileges. This affects Windows systems and can be exploited by authorized users. To protect your network, ensure you have the latest Windows updates installed.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
microsoft windows 10 version 1607 < 10.0.14393.9339
microsoft windows 10 version 1809 < 10.0.17763.9020
microsoft windows 10 version 21h2 < 10.0.19044.7548
microsoft windows 10 version 22h2 < 10.0.19045.7548
microsoft windows 11 version 24h2 < 10.0.26100.8875
microsoft windows 11 version 25h2 < 10.0.26100.8875
microsoft windows 11 version 26h1 < 10.0.28000.2525
microsoft windows server 2012 < 6.2.9200.26226
microsoft windows server 2012 (server core installation) < 6.2.9200.26226
microsoft windows server 2012 r2 < 6.3.9600.23291
microsoft windows server 2012 r2 (server core installation) < 6.3.9600.23291
microsoft windows server 2016 < 10.0.14393.9339
microsoft windows server 2016 (server core installation) < 10.0.14393.9339
microsoft windows server 2019 < 10.0.17763.9020
microsoft windows server 2019 (server core installation) < 10.0.17763.9020
microsoft windows server 2022 < 10.0.20348.5386
microsoft windows server 2025 < 10.0.26100.33158
microsoft windows server 2025 (server core installation) < 10.0.26100.33158
microsoft windows_10_1607 < 10.0.14393.9339
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
microsoft windows_10_1809 < 10.0.17763.9020
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
microsoft windows_10_21h2 < 10.0.19044.7548
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
microsoft windows_10_22h2 < 10.0.19045.7548
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
microsoft windows_11_24h2 < 10.0.26100.8875
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
microsoft windows_11_25h2 < 10.0.26200.8875
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
microsoft windows_11_26h1 < 10.0.28000.2269
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
microsoft windows_server_2012 r2
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
microsoft windows_server_2016 < 10.0.14393.9339
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*
microsoft windows_server_2019 < 10.0.17763.9020
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*
microsoft windows_server_2022 < 10.0.20348.5386
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:x64:*
microsoft windows_server_2025 < 10.0.26100.33158
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*
Original title
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Original description
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
mitre CVSS3.1 9.9
Vulnerability type
CWE-416 Use After Free
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026