CVE-2026-69384
massNull Pointer Dereference DoS in Microsoft Virtual Hard Disk (VHD) Miniport Driver
CVE-2026-69384 is a null pointer dereference (CWE-476) in the Virtual Hard Disk (VHD) Miniport Driver, the Microsoft Windows component that services virtual hard disk operations. A local, unauthenticated attacker can reach the flawed code path with no user interaction required (CVSS: AV:L/AC:L/PR:N/UI:N), and the changed scope with high availability impact indicates the crash extends beyond the driver itself to the host system. The attacker gains denial of service only — confidentiality and integrity are unaffected (C:N/I:N/A:H), producing a CVSS 3.1 base score of 7.1 (high). Anyone running affected Windows releases that include this driver is exposed; the available data does not enumerate specific affected version ranges, so defenders should consult Microsoft's advisory. There is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.4% 30-day exploitation probability (35th percentile), so the current exploitation status is 'none known'.
What to do: Check the MSRC advisory for CVE-2026-69384 to identify the affected Windows versions and apply the corresponding security update as soon as it ships. Until patched, limit execution of untrusted local code on hosts that rely on VHD attachments, since exploitation requires local unauthenticated access and only causes denial of service. Given the low EPSS score (0.4%) and absence of a public PoC or KEV listing, near-term risk appears low, but monitor for exploit releases and KEV addition.
| Microsoft Virtual Hard Disk (VHD) Miniport Driver (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally.
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.