CVE-2026-69681
massHeap Buffer Overflow in Microsoft Windows VHD Miniport Driver (Elevation of Privilege)
CVE-2026-69681 is a heap-based buffer overflow (CWE-122) in Microsoft's Virtual Hard Disk (VHD) Miniport Driver, the Windows component that parses and mounts VHD/VHDX disk images. A low-privileged attacker can trigger the flaw over the network by getting a maliciously crafted VHD image processed on the target — the CVSS vector requires user interaction, consistent with a user mounting an attacker-supplied disk file — causing an out-of-bounds write on the heap during parsing. Successful exploitation allows the authorized attacker to elevate privileges, with high potential impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.0, High). Any Windows system that processes VHD images through the miniport driver is affected; the source data does not specify exact Windows version ranges. No exploitation is known: the flaw is not in CISA KEV, no public PoC exists, and EPSS estimates only a 0.8% chance of exploitation within 30 days.
What to do: Install Microsoft's security update for this vulnerability as soon as it is released and confirm the updated VHD Miniport Driver version against Microsoft's advisory, since the source data provides no specific build numbers. Until patched, avoid mounting VHD/VHDX images from untrusted sources and restrict which low-privileged users can attach virtual disks. Given the absence of a public PoC and a low EPSS score, treat this as routine patch-cycle work rather than an emergency.
| Microsoft Windows (Virtual Hard Disk (VHD) Miniport Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.