CVE-2026-81355
massHeap Buffer Overflow in Microsoft Windows VHD Miniport Driver Allows Local Code Execution
Microsoft's Virtual Hard Disk (VHD) Miniport Driver contains a heap-based buffer overflow (CWE-122) that allows an authorized attacker to execute code locally. Exploitation requires an attacker who already holds high privileges (administrator-level access) on the local machine, and the attack complexity is rated high, meaning specific conditions must align; no user interaction is needed. Successful exploitation yields code execution with a scope-changed rating, indicating the bug crosses a security boundary (such as user-to-kernel), with high impact on confidentiality, integrity, and availability. Potentially affected are Microsoft Windows systems containing the VHD Miniport Driver component, though the provided data does not specify affected version ranges. There is no evidence of exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days (12th percentile).
What to do: Apply Microsoft's fix for CVE-2026-81355 via Windows Update when released, and verify exact affected Windows versions and KBs against Microsoft's advisory, as they are not in the available data. Given that exploitation requires local administrator privileges and there is no known in-the-wild exploitation or public PoC, this fits standard patch-cycle prioritization, but accelerate on shared or multi-user systems where broad local admin rights exist. As an interim mitigation, restrict local administrator access on sensitive hosts.
| Microsoft Windows (Virtual Hard Disk (VHD) Miniport Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.