ZeroHour

CVE-2026-69611

mass

Use-After-Free in Microsoft Windows VHD Miniport Driver Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69611 is a use-after-free memory-safety flaw (CWE-416) in the Windows Virtual Hard Disk (VHD) Miniport Driver, an inbox Microsoft Windows component used for handling virtual hard disk operations. An authorized attacker, meaning someone who already has a valid low-privileged local account on the target machine, can trigger the flaw through local activity against the driver and gain elevated privileges on that host. The high CVSS 3.1 score of 7.0 (local attack vector, high attack complexity, no user interaction required) reflects a privilege-escalation bug that is typically chained with other access rather than a remote entry point. Any Windows system running the affected VHD Miniport Driver is potentially affected, though the driver is only exercised when virtual hard disk functionality is in use. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation in the next 30 days (17th percentile).

What to do: Apply the Windows security update addressing CVE-2026-69611 via Windows Update/WSUS/SCCM as part of your regular patch cycle, prioritizing multi-user hosts, servers, and endpoints where untrusted or low-privileged local users can sign in. Confirm the exact affected Windows versions and fixed builds in Microsoft's advisory before scheduling, since version details are not included in the summary data. Because exploitation requires local credentials, high attack complexity, and no in-the-wild exploitation or public PoC is known, standard-cadence patching is a reasonable posture; restricting local logon rights on sensitive systems adds defense in depth.

Affected
Microsoft Windows (VHD Miniport Driver)
Estimated exposure
mass≈1 billion+ Windows devices (VHD Miniport Driver is an inbox component shipped with Windows) — The VHD Miniport Driver is a standard inbox component of modern Windows client and server releases, and the Windows install base is on the order of a billion-plus devices, so the potentially exposed population is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.