CVE-2026-69611
massUse-After-Free in Microsoft Windows VHD Miniport Driver Enables Local Privilege Escalation
CVE-2026-69611 is a use-after-free memory-safety flaw (CWE-416) in the Windows Virtual Hard Disk (VHD) Miniport Driver, an inbox Microsoft Windows component used for handling virtual hard disk operations. An authorized attacker, meaning someone who already has a valid low-privileged local account on the target machine, can trigger the flaw through local activity against the driver and gain elevated privileges on that host. The high CVSS 3.1 score of 7.0 (local attack vector, high attack complexity, no user interaction required) reflects a privilege-escalation bug that is typically chained with other access rather than a remote entry point. Any Windows system running the affected VHD Miniport Driver is potentially affected, though the driver is only exercised when virtual hard disk functionality is in use. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation in the next 30 days (17th percentile).
What to do: Apply the Windows security update addressing CVE-2026-69611 via Windows Update/WSUS/SCCM as part of your regular patch cycle, prioritizing multi-user hosts, servers, and endpoints where untrusted or low-privileged local users can sign in. Confirm the exact affected Windows versions and fixed builds in Microsoft's advisory before scheduling, since version details are not included in the summary data. Because exploitation requires local credentials, high attack complexity, and no in-the-wild exploitation or public PoC is known, standard-cadence patching is a reasonable posture; restricting local logon rights on sensitive systems adds defense in depth.
| Microsoft Windows (VHD Miniport Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.