CVE-2026-69420
massHeap buffer overflow in Windows VOLSNAP.SYS allows local privilege escalation
CVE-2026-69420 is a heap-based buffer overflow (CWE-122) in VOLSNAP.SYS, the Windows Volume Shadow Copy (volume snapshot) kernel driver. An authorized local user can trigger the flaw by interacting with volume snapshot functionality, corrupting heap memory in the driver; no user interaction beyond local execution is required. Successful exploitation lets the attacker elevate privileges locally, gaining high-privilege (kernel-level) control over the affected machine. Any Windows system running the affected driver is exposed — Microsoft has not published specific affected version ranges in the available data. There is currently no known public proof-of-concept, it is not listed in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: No fixed version numbers or KB identifiers were included in the available data, so monitor the Microsoft Security Response Center advisory for CVE-2026-69420 and install the fix via Windows Update as soon as Microsoft releases it. Until patched, reduce exposure by restricting local logon rights on sensitive servers and prioritizing multi-user hosts (terminal/RDS servers, shared workstations) where untrusted or low-privileged users can run code. Because exploitation requires local access, internet-facing exposure is not the concern; focus on who can authenticate locally to each Windows host.
| Microsoft Windows (VOLSNAP.SYS Volume Shadow Copy driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.