CVE-2026-69347
massHeap-Based Buffer Overflow in Windows Fast FAT Driver Allows Local Code Execution
CVE-2026-69347 is a heap-based buffer overflow (CWE-122) in the Windows Fast FAT driver, the in-box kernel component Microsoft Windows uses to mount and parse FAT file system volumes. The flaw is triggered when the driver processes malformed or specially crafted FAT file system data, and the CVSS vector (AV:L/AC:H/PR:N/UI:N) indicates the attack path is local, relatively complex to exploit, but requires no privileges or user interaction. A successful exploit allows an unauthorized local attacker to execute code with high impact on confidentiality, integrity, and availability. Any Windows system running the affected Fast FAT driver is potentially affected, though Microsoft's advisory in this data does not specify which Windows versions or releases are impacted. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, indicating no known in-the-wild exploitation.
What to do: Apply Microsoft's security update for this component through Windows Update as soon as it is available, and consult Microsoft's advisory to identify exactly which Windows versions are affected. Until patched, prioritize shared, multi-user, and high-value systems that accept untrusted removable media or untrusted FAT volumes, since exploitation requires local access. Consider restricting or scanning untrusted USB and removable storage as an interim mitigation and monitor for an updated EPSS score or KEV listing.
| Microsoft Windows Fast FAT Driver (in-box Windows file system driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.