ZeroHour

CVE-2026-69619

mass

Out-of-bounds read in Windows exFAT driver allows network privilege elevation

CVSS 3.1
8.0 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69619 is an out-of-bounds read (CWE-125) in the Windows exFAT File System component, assigned by Microsoft with a CVSS 3.1 score of 8.0 (High). An authorized (low-privilege) attacker can trigger the flaw over a network, with user interaction required per the CVSS vector, most plausibly when a system processes attacker-influenced exFAT metadata such as a mounted network volume or removable media. Successful exploitation permits elevation of privilege, with high impact on confidentiality, integrity, and availability according to the scoring. Potentially affected are Windows installations that include the exFAT driver, though the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory. There is currently no known exploitation, no public proof of concept, no CISA KEV listing, and EPSS estimates a 0.8% probability of exploitation within 30 days (53rd percentile).

What to do: Apply Microsoft's exFAT/filesystem security update for your Windows builds as soon as released, and check Microsoft's advisory for the exact affected version ranges since they are not listed here. In the interim, restrict mounting of untrusted exFAT volumes (network shares, USB/SD media) by low-privilege users and remind users not to interact with untrusted removable media. Monitor Microsoft's advisory and CISA KEV for changes in affected builds or exploitation status.

Affected
Microsoft Windows exFAT File System (exFAT driver)
Estimated exposure
mass>1,000,000 Windows systems (exFAT driver is a default Windows component; Windows installed base exceeds 1 billion devices) — The exFAT filesystem driver ships as a standard component of Windows, which runs on well over a billion devices worldwide, so any affected release spans a mass-scale installed base, although only systems that actually parse untrusted exFAT…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.