Junglewise Threat Intelligence

CVE-2026-40380: Microsoft Windows heap overflow in Volume Manager Extension Driver

CVE-2026-40380 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Windows Volume Manager Extension Driver, which is responsible for managing storage volumes. An attacker with physical access to a device and high-level administrative privileges could exploit this flaw to execute unauthorized code. This could lead to a complete compromise of the system's confidentiality, integrity, and availability.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Volume Manager Extension Driver of Microsoft Windows. The vulnerability is triggered by improper handling of memory during volume management operations, potentially involving numeric truncation (CWE-197) or out-of-bounds reads (CWE-125). To exploit this, an attacker requires physical access to the target machine and must already possess high-level administrative privileges (PR:H). Successful exploitation allows for arbitrary code execution at the kernel level, leading to full system compromise. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Published by Microsoft and NVD

References

Related threats