CVE-2026-56172
massUse-After-Free Local Privilege Escalation in Microsoft Windows VHD Miniport Driver
CVE-2026-56172 is a use-after-free memory-safety flaw (CWE-416) in the Windows VHD miniport driver, the in-box component that handles virtual hard disk (VHD/VHDX) operations. A local attacker who is already authorized on the machine with low privileges can trigger the dangling-memory condition and leverage it to execute code with elevated privileges, with no user interaction required. Any Windows system containing this driver is affected, with the highest risk on multi-user systems such as servers, VDI hosts, or workstations where untrusted or low-privileged users can sign in. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation within 30 days (25th percentile). Microsoft, acting as the CVE numbering authority, has not disclosed detailed trigger mechanics or affected version ranges in the available data.
What to do: Apply Microsoft's security update for CVE-20256172 as soon as it is released via Windows Update/WSUS, checking Microsoft's advisory for the exact affected builds since version ranges are not listed in this data. Until patched, limit local logon rights to trusted users on shared systems, terminal servers, and VDI hosts, and prioritize patching Windows Server and multi-user machines where local privilege escalation has the greatest impact. Monitor vendor channels for exploit activity given that exploitation dynamics can change quickly after a public PoC appears.
| Microsoft Windows (VHD miniport driver component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.