ZeroHour

CVE-2026-69291

mass

Heap Buffer Overflow RCE in Microsoft Windows Volume Manager Extension Driver

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-69291 is a heap-based buffer overflow (CWE-122) in the Windows Volume Manager Extension Driver, a component of Microsoft Windows. An unauthorized attacker can trigger the flaw remotely over a network; the CVSS vector indicates no special privileges are required, but user interaction (UI:R) is needed, suggesting the victim must take some action for the attack to complete. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, consistent with compromise of the driver's execution context. Any Windows system with the affected Volume Manager Extension Driver component is potentially affected, though the data does not specify which Windows releases. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a modest 0.6% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Apply Microsoft's security update for this CVE as part of your regular monthly patch cycle; this data does not include a specific KB or fixed version, so consult Microsoft's advisory for the definitive list of affected Windows releases and the correct update. Because exploitation requires user interaction per the CVSS vector, reinforce user awareness around unexpected system prompts and review which critical hosts have the Volume Manager Extension Driver loaded. There is no public PoC or known in-the-wild exploitation, but EPSS may shift if details emerge, so monitor for updated guidance.

Affected
Microsoft Windows (Volume Manager Extension Driver)
Estimated exposure
massplausibly on the order of hundreds of millions to 1+ billion Windows devices, though the subset with the vulnerable driver active is unknown — Windows runs on over a billion active devices per public installed-base estimates and the Volume Manager component ships with the OS, so the worst-case exposed population is very large even though per-configuration counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.