CVE-2026-69432
—Heap Buffer Overflow in Microsoft Volume Manager Driver Allows Local Privilege Escalation
CVE-2026-69432 is a heap-based buffer overflow (CWE-122) in Microsoft's Volume Manager Driver that allows an authorized attacker to elevate privileges locally. The flaw is triggered when a locally authenticated, low-privileged process interacts with the driver in a way that corrupts heap memory, and the CVSS impact ratings (high confidentiality, integrity, and availability) indicate a successful exploit yields near-complete control of the affected system. Because the attack vector is local, an attacker must already be able to execute code on the machine, for example through malware or a compromised user account, and then use this bug to escalate privileges. Any system running the vulnerable Volume Manager Driver is affected, though the available data does not specify which product versions or builds are impacted. There is currently no evidence of exploitation: no public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days.
What to do: Check Microsoft's security advisory for the exact affected Volume Manager Driver builds and install the corresponding patch as soon as it is released; because affected versions are not enumerated here, do not assume your fleet is unaffected. In the meantime, restrict interactive logon rights on multi-user systems and watch for anomalous local privilege-escalation activity. The low EPSS score and absence of KEV listing make this a routine patch-cycle priority rather than an emergency, unless your environment is exposed to untrusted local users.
| Microsoft Volume Manager Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.