CVE-2026-69427
massOut-of-Bounds Read in Microsoft Windows VOLSNAP.SYS Enables Network Privilege Escalation
CVE-2026-69427 is an out-of-bounds read (CWE-125) in VOLSNAP.SYS, the Windows kernel driver that implements Volume Shadow Copy (snapshot) functionality. A low-privileged, authorized attacker can trigger the flaw over a network — the CVSS vector indicates user interaction is required — causing the driver to read memory beyond the bounds of a buffer. Successful exploitation allows the attacker to elevate privileges on the target host, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0, High). Any Windows installation shipping the affected version of VOLSNAP.SYS is potentially affected; the available data does not specify affected versions, so Microsoft's advisory should be consulted for the authoritative list. As of this analysis there is no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not in the CISA KEV catalog; EPSS currently estimates a 0.7% probability of exploitation within 30 days (51st percentile).
What to do: Apply the Microsoft security update addressing CVE-2026-69427 via Windows Update on all Windows client and server systems once released, prioritizing internet-reachable and multi-user hosts. Until patched, restrict low-privileged network access to trusted accounts and treat Windows privilege-escalation alerts as high priority. Because no version list is provided in this data, verify the affected-version details in Microsoft's official advisory before scoping remediation.
| Microsoft Windows (VOLSNAP.SYS Volume Snapshot driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.