CVE-2026-70574
massOut-of-Bounds Read in Microsoft VHD Miniport Driver Enables Local Privilege Escalation
CVE-2026-70574 is an out-of-bounds read (CWE-125) in the Microsoft Virtual Hard Disk (VHD) Miniport Driver, the Windows component that handles virtual hard disk images. A local, authorized user with low privileges can trigger the flaw, causing the driver to read beyond the bounds of a buffer while processing virtual disk data. Successful exploitation elevates the attacker's privileges on the local system, with high confidentiality, integrity, and availability impact per the CVSS 3.1 vector (7.8 High, AV:L/PR:L/UI:N). Any Windows system with the VHD Miniport Driver enabled is potentially affected; Microsoft (the assigning CNA) has not specified affected version ranges in the available data. There are no known public proofs-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Watch Microsoft's advisory for the definitive list of affected Windows versions (not provided here) and install the fix via Windows Update when it is released. Because exploitation requires low-privileged local access, prioritize patching shared, multi-user systems such as RDS hosts, VDI environments, and workstations where untrusted users can sign in or run code. No public PoC or in-the-wild exploitation is known, so this can be handled in normal patch cycles if you do not host untrusted local users.
| Microsoft Virtual Hard Disk (VHD) Miniport Driver (Microsoft Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.