Microsoft Windows Virtualization-Based Security Enclave Security Feature Bypass Vulnerability

Vulnerability

A vulnerability allowing an authorized attacker to bypass a security feature has been identified in the Windows Virtualization-Based Security (VBS) Enclave. This vulnerability arises from an untrusted pointer dereference, which can be exploited locally. By successfully exploiting this vulnerability, an attacker could bypass the Virtual Secure Mode (VSM) isolation between Virtual Trust Level 0 (VTL0) and Virtual Trust Level 1 (VTL1). This could enable a compromised Windows kernel to alter memory belonging to the secure kernel, undermining the isolation guarantees that VBS is designed to provide.

Impact

Exploitation of this vulnerability could lead to a security feature bypass, allowing unauthorized modifications to memory in the secure kernel, thereby breaking the intended isolation provided by VBS.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked in the product update information.

Added: Apr 14, 2026, 11:02 PM
Updated: Apr 14, 2026, 11:02 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
3.3
exploitability
2.8
remediation
7.7
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.