ZeroHour

CVE-2026-69541

mass

Local Privilege Escalation via Heap Overflow in Microsoft Windows VHD Miniport Driver

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

The Virtual Hard Disk (VHD) Miniport Driver, the Windows component that processes virtual hard disk images, contains a heap-based buffer overflow (CWE-122). An attacker who already has a low-privileged, authorized account on a machine can trigger the flaw locally, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, giving high impact on the confidentiality, integrity, and availability of the host. Any Windows release that ships the VHD Miniport Driver is potentially affected, with exact version ranges listed in Microsoft's advisory. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, prioritizing multi-user systems such as RDS/VDI hosts, shared workstations, and machines that run untrusted code or third-party virtual disk workloads. Confirm the patch is deployed on all Windows clients and servers, since the affected driver is an inbox component and may be present even where VHDs are not actively used. No workaround is published; restrict local logon and untrusted code execution on sensitive hosts until patched.

Affected
Microsoft Windows (Virtual Hard Disk (VHD) Miniport Driver)
Estimated exposure
mass>1 billion Windows installations (driver ships as a built-in Windows component) — The VHD Miniport Driver is an inbox Windows component, and Windows runs on well over a billion devices worldwide, so effectively every unpatched Windows client or server install is affected, though exploitation requires local access by an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.