ZeroHour

CVE-2026-69347

mass

Heap-Based Buffer Overflow in Windows Fast FAT Driver Allows Local Code Execution

CVSS 3.1
7.4 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-69347 is a heap-based buffer overflow (CWE-122) in the Windows Fast FAT driver, the in-box kernel component Microsoft Windows uses to mount and parse FAT file system volumes. The flaw is triggered when the driver processes malformed or specially crafted FAT file system data, and the CVSS vector (AV:L/AC:H/PR:N/UI:N) indicates the attack path is local, relatively complex to exploit, but requires no privileges or user interaction. A successful exploit allows an unauthorized local attacker to execute code with high impact on confidentiality, integrity, and availability. Any Windows system running the affected Fast FAT driver is potentially affected, though Microsoft's advisory in this data does not specify which Windows versions or releases are impacted. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, indicating no known in-the-wild exploitation.

What to do: Apply Microsoft's security update for this component through Windows Update as soon as it is available, and consult Microsoft's advisory to identify exactly which Windows versions are affected. Until patched, prioritize shared, multi-user, and high-value systems that accept untrusted removable media or untrusted FAT volumes, since exploitation requires local access. Consider restricting or scanning untrusted USB and removable storage as an interim mitigation and monitor for an updated EPSS score or KEV listing.

Affected
Microsoft Windows Fast FAT Driver (in-box Windows file system driver)
Estimated exposure
mass≈1 billion+ Windows installations (Fast FAT driver is a standard in-box kernel component of Windows) — The Fast FAT driver ships with essentially all Windows installations and Windows runs on well over a billion devices worldwide, though actual exploitability requires local access to a crafted FAT volume rather than network exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.