CVE-2025-29955: Windows Hyper-V Denial of Service Vulnerability
Overview
- Severity
- Medium (CVSS 6.2)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- Category
- Denial of Service
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2025-May
- Released
- 2025-05-13
- EPSS Score
- 0.99% (percentile: 76.9%)
Description
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
Affected Products (4)
Windows
- Windows Server 2025 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
- Windows 11 Version 24H2 for x64-based Systems
- Windows Server 2025
Security Updates (3)
Acknowledgments
MORSE with <a href="https://microsoft.com/">Microsoft</a>
Revision History
- 2025-05-13: Information published.