ZeroHour

CVE-2026-69432

Heap Buffer Overflow in Microsoft Volume Manager Driver Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69432 is a heap-based buffer overflow (CWE-122) in Microsoft's Volume Manager Driver that allows an authorized attacker to elevate privileges locally. The flaw is triggered when a locally authenticated, low-privileged process interacts with the driver in a way that corrupts heap memory, and the CVSS impact ratings (high confidentiality, integrity, and availability) indicate a successful exploit yields near-complete control of the affected system. Because the attack vector is local, an attacker must already be able to execute code on the machine, for example through malware or a compromised user account, and then use this bug to escalate privileges. Any system running the vulnerable Volume Manager Driver is affected, though the available data does not specify which product versions or builds are impacted. There is currently no evidence of exploitation: no public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days.

What to do: Check Microsoft's security advisory for the exact affected Volume Manager Driver builds and install the corresponding patch as soon as it is released; because affected versions are not enumerated here, do not assume your fleet is unaffected. In the meantime, restrict interactive logon rights on multi-user systems and watch for anomalous local privilege-escalation activity. The low EPSS score and absence of KEV listing make this a routine patch-cycle priority rather than an emergency, unless your environment is exposed to untrusted local users.

Affected
Microsoft Volume Manager Driver
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.