CVE-2026-77904
massHeap Buffer Overflow in Microsoft Windows Volume Manager Extension Driver
CVE-2026-77904 is a heap-based buffer overflow (CWE-122) in the Windows Volume Manager Extension Driver, a storage/volume component shipped with Microsoft Windows. The flaw is triggered locally when the driver mishandles input, and it can only be exploited by an attacker who already has an authorized, low-privileged account on the target machine. Successful exploitation lets the attacker elevate their privileges locally, gaining high-integrity (kernel-adjacent) access with full read/write/execute impact on the system. Any Windows installation containing the vulnerable driver is affected; Microsoft, acting as the CNA, has assigned the issue a CVSS 3.1 score of 7.8 (High). Exploitation is currently not observed: there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
What to do: Monitor Microsoft's advisory and apply the fix via Windows Update as soon as it is released for your Windows edition, prioritizing shared or multi-user hosts where local accounts are common. Until patched, limit local logon rights on sensitive systems and review which machines expose interactive access to non-admin users. Watch for updates to EPSS or KEV listings, as those would signal rising exploitation risk.
| Microsoft Windows (Volume Manager Extension Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.