ZeroHour

CVE-2026-68878

mass

Stack buffer overflow in Windows Fast FAT driver enables privilege escalation

CVSS 3.1
8.0 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-68878 is a stack-based buffer overflow (CWE-121) in the Windows Fast FAT filesystem driver, the kernel component responsible for parsing FAT-formatted volumes. According to Microsoft, an authorized attacker (low privileges required, per the CVSS vector) can trigger the flaw over a network to elevate privileges; the CVSS vector also indicates user interaction is required, consistent with a crafted FAT volume or image being mounted and parsed by the driver. A successful exploit yields kernel-level elevation of privilege with high confidentiality, integrity, and availability impact (CVSS 8.0, High). Any Windows system containing the Fast FAT driver is affected, though the source data does not specify version ranges, so defenders should consult Microsoft's advisory for the exact affected builds. As of this writing there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile).

What to do: Apply Microsoft's Windows security update for CVE-2026-68878 as soon as it is released, verifying affected builds against the Microsoft advisory and deploying via Windows Update. Until patched, restrict mounting of FAT-formatted removable media, network-mounted FAT volumes, or disk images from untrusted sources on user workstations. Monitor CISA KEV and EPSS for changes, as exploitation likelihood may rise if a public PoC emerges.

Affected
Microsoft Windows Fast FAT filesystem driver (fastfat.sys)
Estimated exposure
mass≈1 billion+ Windows installations (stock Windows component; Windows installed base on the order of 1.4 billion devices) — The Fast FAT driver ships with Windows as a standard component, and Microsoft's publicly reported Windows device base is roughly 1.4 billion, so every unpatched Windows system is plausibly affected, though exploitation additionally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.