ZeroHour

CVE-2026-69582

mass

Windows Volume Manager Extension Driver Buffer Over-Read Grants Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69582 is a buffer over-read (CWE-126) in the Windows Volume Manager Extension Driver, a component that handles volume-management requests in Windows. The flaw is triggered locally by an attacker who already has low-privilege access to a vulnerable Windows system, causing the driver to read beyond the bounds of a buffer. Successful exploitation allows the attacker to elevate their privileges on the local machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 7.8, High). All Windows systems running the affected builds listed in Microsoft's advisory are exposed; the provided data does not enumerate specific Windows versions, and the vulnerable driver is a standard Windows component, so the potentially affected installed base is very large. There is currently no evidence of exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-69582 as soon as it is available via Windows Update, and consult Microsoft's advisory to identify which Windows builds and driver versions are affected. Until patched, prioritize servers and shared/multi-user endpoints (e.g., RDS hosts, kiosk machines) where low-privileged local users are present, since exploitation requires only local access with low privileges. Monitor the Microsoft advisory and threat feeds for any emergence of public exploit code, given the currently low EPSS score.

Affected
Microsoft Windows (Volume Manager Extension Driver)
Estimated exposure
mass≈1 billion+ Windows devices (order of the Windows installed base, pending version scoping from Microsoft's advisory) — The Windows installed base exceeds a billion devices and the Volume Manager Extension Driver is a built-in Windows component, so potential exposure is plausibly on the order of the entire Windows fleet, though Microsoft's advisory will…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-126
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.