ZeroHour

CVE-2026-69426

mass

Heap Buffer Overflow in Microsoft Windows VOLSNAP.SYS Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69426 is a heap-based buffer overflow (CWE-122) in VOLSNAP.SYS, the Windows kernel-mode driver that handles volume shadow copy (snapshot) operations. The CVSS vector (AV:L/AC:L/PR:L/UI:N) indicates it is triggered locally by an authorized, low-privileged attacker with no user interaction required. Successful exploitation results in code execution with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 7.8, High); because VOLSNAP.SYS is a kernel driver, this effectively means elevation of privilege on the local system. Any Windows system running a vulnerable copy of the driver is affected, although the available data does not enumerate specific Windows versions or builds. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Monitor Microsoft's Security Update Guide for the affected Windows version ranges and apply the vendor patch (via the corresponding cumulative update) as soon as it is published. Prioritize multi-user systems where untrusted local code runs, such as RDS/session hosts, shared workstations, and admin jump servers, since exploitation requires local access with low privileges. Given no known exploitation or public PoC, handling this at normal patch cadence is reasonable, but re-check advisories if exploitation activity emerges.

Affected
Microsoft Windows (VOLSNAP.SYS volume snapshot driver)
Estimated exposure
masshundreds of millions of Windows systems potentially exposed (driver ships with Windows client and server editions; >1M) — VOLSNAP.SYS is a standard component of Windows, so the theoretical affected population is on the order of the global Windows installed base (over a billion devices), though Microsoft's list of affected versions would narrow the actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.