CVE-2026-69573
massUse-after-free local privilege escalation in Windows UDFS driver
CVE-2026-69573 is a use-after-free vulnerability (CWE-416) in the Windows Universal Disk Format File System Driver (UDFS), the inbox Windows component that handles UDF-formatted volumes such as optical media and disk images. It is triggered by local activity against a UDF file system, in which the driver frees memory that is subsequently reused; the high attack complexity (AC:H) indicates that exploitation depends on specific conditions or timing rather than straightforward input. A low-privileged local ("authorized") attacker who successfully triggers the flaw can elevate privileges on the machine, with high impact to confidentiality, integrity, and availability on that system. Because UDFS ships with Windows, the general Windows installed base is affected, though the specific Windows versions are not stated in the available data. There is no known exploitation to date: no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Monitor Microsoft's advisory for CVE-2026-69573 and apply the corresponding Windows security update as soon as it is released; fixed build numbers are not included in the available data. Until patched, prioritize systems where untrusted or low-privileged users have local access or can mount UDF-formatted media and images. Given the local attack vector, high complexity, and no known exploitation, treat this as routine patch-cycle remediation rather than an emergency.
| Microsoft Windows (Universal Disk Format File System Driver, UDFS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.