ZeroHour

CVE-2026-56172

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows VHD Miniport Driver

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-56172 is a use-after-free memory-safety flaw (CWE-416) in the Windows VHD miniport driver, the in-box component that handles virtual hard disk (VHD/VHDX) operations. A local attacker who is already authorized on the machine with low privileges can trigger the dangling-memory condition and leverage it to execute code with elevated privileges, with no user interaction required. Any Windows system containing this driver is affected, with the highest risk on multi-user systems such as servers, VDI hosts, or workstations where untrusted or low-privileged users can sign in. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation within 30 days (25th percentile). Microsoft, acting as the CVE numbering authority, has not disclosed detailed trigger mechanics or affected version ranges in the available data.

What to do: Apply Microsoft's security update for CVE-20256172 as soon as it is released via Windows Update/WSUS, checking Microsoft's advisory for the exact affected builds since version ranges are not listed in this data. Until patched, limit local logon rights to trusted users on shared systems, terminal servers, and VDI hosts, and prioritize patching Windows Server and multi-user machines where local privilege escalation has the greatest impact. Monitor vendor channels for exploit activity given that exploitation dynamics can change quickly after a public PoC appears.

Affected
Microsoft Windows (VHD miniport driver component)
Estimated exposure
masshundreds of millions of Windows installations (in-box driver component; Windows installed base exceeds ~1 billion devices) — The VHD miniport driver ships as an in-box Windows component, so exposure scales with the overall Windows installed base, publicly estimated at over a billion devices, though practical risk is limited to machines where low-privileged local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.