CVE-2026-69426
massHeap Buffer Overflow in Microsoft Windows VOLSNAP.SYS Allows Local Code Execution
CVE-2026-69426 is a heap-based buffer overflow (CWE-122) in VOLSNAP.SYS, the Windows kernel-mode driver that handles volume shadow copy (snapshot) operations. The CVSS vector (AV:L/AC:L/PR:L/UI:N) indicates it is triggered locally by an authorized, low-privileged attacker with no user interaction required. Successful exploitation results in code execution with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 7.8, High); because VOLSNAP.SYS is a kernel driver, this effectively means elevation of privilege on the local system. Any Windows system running a vulnerable copy of the driver is affected, although the available data does not enumerate specific Windows versions or builds. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Monitor Microsoft's Security Update Guide for the affected Windows version ranges and apply the vendor patch (via the corresponding cumulative update) as soon as it is published. Prioritize multi-user systems where untrusted local code runs, such as RDS/session hosts, shared workstations, and admin jump servers, since exploitation requires local access with low privileges. Given no known exploitation or public PoC, handling this at normal patch cadence is reasonable, but re-check advisories if exploitation activity emerges.
| Microsoft Windows (VOLSNAP.SYS volume snapshot driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.