CVE-2026-69541
massLocal Privilege Escalation via Heap Overflow in Microsoft Windows VHD Miniport Driver
The Virtual Hard Disk (VHD) Miniport Driver, the Windows component that processes virtual hard disk images, contains a heap-based buffer overflow (CWE-122). An attacker who already has a low-privileged, authorized account on a machine can trigger the flaw locally, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, giving high impact on the confidentiality, integrity, and availability of the host. Any Windows release that ships the VHD Miniport Driver is potentially affected, with exact version ranges listed in Microsoft's advisory. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE as soon as it is available, prioritizing multi-user systems such as RDS/VDI hosts, shared workstations, and machines that run untrusted code or third-party virtual disk workloads. Confirm the patch is deployed on all Windows clients and servers, since the affected driver is an inbox component and may be present even where VHDs are not actively used. No workaround is published; restrict local logon and untrusted code execution on sensitive hosts until patched.
| Microsoft Windows (Virtual Hard Disk (VHD) Miniport Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.