CVE-2026-69561
massOut-of-Bounds Read in Windows CD-ROM Driver Enables Local Privilege Escalation
CVE-2026-69561 is an out-of-bounds read (CWE-125) in the Windows CD-ROM driver, rated CVSS 3.1 7.8 (high) with a local attack vector and low privileges required. An attacker who already has low-privileged authorized access on a Windows machine can reach the vulnerable driver code path and cause the kernel to read past the end of an internal buffer. Successful exploitation allows local privilege elevation, granting the attacker elevated rights with high impact to confidentiality, integrity, and availability on the host. Any Windows system running an affected release of the inbox CD-ROM driver is in scope; the provided data does not specify which Windows versions are affected, so defenders should consult Microsoft's advisory. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.3% probability of exploitation within the next 30 days.
What to do: Apply Microsoft's security update for the affected Windows releases as soon as it is published, and verify installed builds against the affected-products table in Microsoft's advisory since version ranges are not yet specified here. Because exploitation requires local low-privileged access, prioritize hosts that expose local logon or Remote Desktop to untrusted or low-privilege users. Monitor CISA KEV, EPSS, and Microsoft advisories for updates on exploitation status or added mitigations.
| Microsoft Windows (CD-ROM driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.