CVE-2026-68878
massStack buffer overflow in Windows Fast FAT driver enables privilege escalation
CVE-2026-68878 is a stack-based buffer overflow (CWE-121) in the Windows Fast FAT filesystem driver, the kernel component responsible for parsing FAT-formatted volumes. According to Microsoft, an authorized attacker (low privileges required, per the CVSS vector) can trigger the flaw over a network to elevate privileges; the CVSS vector also indicates user interaction is required, consistent with a crafted FAT volume or image being mounted and parsed by the driver. A successful exploit yields kernel-level elevation of privilege with high confidentiality, integrity, and availability impact (CVSS 8.0, High). Any Windows system containing the Fast FAT driver is affected, though the source data does not specify version ranges, so defenders should consult Microsoft's advisory for the exact affected builds. As of this writing there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile).
What to do: Apply Microsoft's Windows security update for CVE-2026-68878 as soon as it is released, verifying affected builds against the Microsoft advisory and deploying via Windows Update. Until patched, restrict mounting of FAT-formatted removable media, network-mounted FAT volumes, or disk images from untrusted sources on user workstations. Monitor CISA KEV and EPSS for changes, as exploitation likelihood may rise if a public PoC emerges.
| Microsoft Windows Fast FAT filesystem driver (fastfat.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.