CVE-2026-69619
massOut-of-bounds read in Windows exFAT driver allows network privilege elevation
CVE-2026-69619 is an out-of-bounds read (CWE-125) in the Windows exFAT File System component, assigned by Microsoft with a CVSS 3.1 score of 8.0 (High). An authorized (low-privilege) attacker can trigger the flaw over a network, with user interaction required per the CVSS vector, most plausibly when a system processes attacker-influenced exFAT metadata such as a mounted network volume or removable media. Successful exploitation permits elevation of privilege, with high impact on confidentiality, integrity, and availability according to the scoring. Potentially affected are Windows installations that include the exFAT driver, though the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory. There is currently no known exploitation, no public proof of concept, no CISA KEV listing, and EPSS estimates a 0.8% probability of exploitation within 30 days (53rd percentile).
What to do: Apply Microsoft's exFAT/filesystem security update for your Windows builds as soon as released, and check Microsoft's advisory for the exact affected version ranges since they are not listed here. In the interim, restrict mounting of untrusted exFAT volumes (network shares, USB/SD media) by low-privilege users and remind users not to interact with untrusted removable media. Monitor Microsoft's advisory and CISA KEV for changes in affected builds or exploitation status.
| Microsoft Windows exFAT File System (exFAT driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.