CVE-2026-69592
massHeap-Based Buffer Overflow in Windows UDFS Driver Allows Local Privilege Escalation
CVE-2026-69592 is a heap-based buffer overflow (CWE-122) in the Windows Universal Disk Format (UDFS) file system driver, a kernel component used to read UDF-formatted discs, removable media, and disc images. A local attacker who already has low-privileged access to a Windows machine could trigger the flaw by having the system process a maliciously crafted UDF volume, with no user interaction required (CVSS: AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker's privileges with high impact on confidentiality, integrity, and availability, effectively yielding full control of the host. Any Windows system shipping the affected UDFS driver is potentially affected, though the provided data does not specify which Windows builds, so defenders should consult Microsoft's advisory for the exact version range. Exploitation status: no public proof of concept, not listed in CISA KEV, and a low EPSS of 0.3% over the next 30 days, indicating no current evidence of in-the-wild attacks.
What to do: Apply the Microsoft security update addressing CVE-2026-69592 as soon as it is available through Windows Update/WSUS, checking Microsoft's advisory for the affected Windows builds. As an interim mitigation, avoid mounting untrusted UDF-formatted discs, USB media, or ISO/UDF images and restrict mounting of removable volumes to trusted users. Given EPSS of 0.3%, no public PoC, and no KEV listing, standard patch cadence is likely sufficient unless hosts routinely process removable media or disc images.
| Microsoft Windows Universal Disk Format (UDFS) File System Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.