ZeroHour

CVE-2026-69468

mass

Heap overflow in Windows Volume Manager Extension Driver (local privilege escalation)

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

The Windows Volume Manager Extension Driver, an inbox kernel component of the Windows storage stack, contains a heap-based buffer overflow (CWE-122). Per the CVSS vector, exploitation requires local access with low privileges and no user interaction, but carries high attack complexity, meaning reliable triggering is difficult; no public proof-of-concept is known. A successful exploit allows an authorized local user to elevate privileges on the host, with high impact to confidentiality, integrity, and availability. Any Windows installation shipping the affected driver is potentially exposed, although the available data does not specify which Windows editions or builds are affected. Exploitation has not been observed in the wild, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a modest ~0.3% probability of exploitation within 30 days.

What to do: Monitor Microsoft's advisory to identify the affected Windows builds and install the corresponding Windows security update as soon as it is available. Because exploitation requires local access with low privileges but no user interaction, prioritize multi-user and locally accessible systems such as RDS/VDI hosts and shared workstations, and verify remediation once updated builds are deployed. With no public PoC or in-the-wild reports, standard patch cadence is adequate, but watch KEV and EPSS for status changes.

Affected
Microsoft Windows Volume Manager Extension Driver (inbox Windows kernel driver)
Estimated exposure
mass≈1+ billion Windows devices (driver ships inbox with Windows) — The Volume Manager Extension Driver is part of the inbox Windows storage stack, so plausible exposure roughly tracks the global Windows installed base of well over 1 billion devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.