ZeroHour

CVE-2026-69549

mass

Out-of-Bounds Read in Windows VHD Miniport Driver Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-69549 is an out-of-bounds read (CWE-125) in the Windows Virtual Hard Disk (VHD) Miniport Driver, the in-box driver that parses and mounts .vhd disk images. A local attacker who already holds low-privileged access must induce the driver to process malformed VHD content — for example by mounting a crafted image — under conditions the attacker only partially controls, reflected in the high attack complexity (AV:L/AC:H/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges on the local machine, with the CWE-200 mapping suggesting information exposure may play a role in the flaw. Because the driver ships with Windows, the affected population is broad, but practical risk concentrates on systems where untrusted users can attach VHD images, such as shared workstations, terminal servers, and VDI hosts. There is no evidence of exploitation: the flaw is not in CISA KEV, no public PoC is known, and EPSS puts the 30-day exploitation probability at just 0.3% (22nd percentile).

What to do: Install Microsoft's patch via Windows Update as soon as it is available, prioritizing multi-user Windows systems (RDS/VDI hosts, shared workstations) where untrusted users can mount VHD files. Until patched, restrict attachment of untrusted VHD images by unprivileged users and monitor for PoC publication given none exists today. Check Microsoft's advisory for the exact affected Windows versions, since the source data does not list them.

Affected
Microsoft Windows (VHD Miniport Driver)
Estimated exposure
mass≈1 billion Windows devices ship the in-box driver; practically exposed subset is hosts where low-privileged local users can mount VHD images — The VHD Miniport Driver is a Windows in-box component and Windows runs on roughly a billion-plus devices, but exploitation requires local access and the ability to trigger VHD parsing, so the realistically exposed set is far smaller than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125, CWE-200
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.