ZeroHour

CVE-2026-69420

mass

Heap buffer overflow in Windows VOLSNAP.SYS allows local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69420 is a heap-based buffer overflow (CWE-122) in VOLSNAP.SYS, the Windows Volume Shadow Copy (volume snapshot) kernel driver. An authorized local user can trigger the flaw by interacting with volume snapshot functionality, corrupting heap memory in the driver; no user interaction beyond local execution is required. Successful exploitation lets the attacker elevate privileges locally, gaining high-privilege (kernel-level) control over the affected machine. Any Windows system running the affected driver is exposed — Microsoft has not published specific affected version ranges in the available data. There is currently no known public proof-of-concept, it is not listed in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation within 30 days.

What to do: No fixed version numbers or KB identifiers were included in the available data, so monitor the Microsoft Security Response Center advisory for CVE-2026-69420 and install the fix via Windows Update as soon as Microsoft releases it. Until patched, reduce exposure by restricting local logon rights on sensitive servers and prioritizing multi-user hosts (terminal/RDS servers, shared workstations) where untrusted or low-privileged users can run code. Because exploitation requires local access, internet-facing exposure is not the concern; focus on who can authenticate locally to each Windows host.

Affected
Microsoft Windows (VOLSNAP.SYS Volume Shadow Copy driver)
Estimated exposure
mass>1 billion Windows devices/installations (driver ships with Windows client and server editions) — VOLSNAP.SYS is a core Windows kernel driver present by default on effectively all Windows client and server deployments, and Windows runs on well over a billion devices worldwide.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.