ZeroHour

CVE-2026-69681

mass

Heap Buffer Overflow in Microsoft Windows VHD Miniport Driver (Elevation of Privilege)

CVSS 3.1
8.0 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69681 is a heap-based buffer overflow (CWE-122) in Microsoft's Virtual Hard Disk (VHD) Miniport Driver, the Windows component that parses and mounts VHD/VHDX disk images. A low-privileged attacker can trigger the flaw over the network by getting a maliciously crafted VHD image processed on the target — the CVSS vector requires user interaction, consistent with a user mounting an attacker-supplied disk file — causing an out-of-bounds write on the heap during parsing. Successful exploitation allows the authorized attacker to elevate privileges, with high potential impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.0, High). Any Windows system that processes VHD images through the miniport driver is affected; the source data does not specify exact Windows version ranges. No exploitation is known: the flaw is not in CISA KEV, no public PoC exists, and EPSS estimates only a 0.8% chance of exploitation within 30 days.

What to do: Install Microsoft's security update for this vulnerability as soon as it is released and confirm the updated VHD Miniport Driver version against Microsoft's advisory, since the source data provides no specific build numbers. Until patched, avoid mounting VHD/VHDX images from untrusted sources and restrict which low-privileged users can attach virtual disks. Given the absence of a public PoC and a low EPSS score, treat this as routine patch-cycle work rather than an emergency.

Affected
Microsoft Windows (Virtual Hard Disk (VHD) Miniport Driver)
Estimated exposure
mass≈1 billion+ Windows installations (Windows' active installed base exceeds 1 billion devices) — The VHD Miniport Driver ships with the Windows operating system across client and server editions, and Windows runs on more than one billion active devices, so essentially every Windows deployment carries the affected component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.