Executive brief
A security vulnerability exists in the Microsoft Windows Volume Manager Extension Driver, which is responsible for managing storage volumes. An attacker with physical access to a device and high-level administrative privileges could exploit this flaw to execute unauthorized code. This could lead to a complete compromise of the system's confidentiality, integrity, and availability.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Volume Manager Extension Driver of Microsoft Windows. The vulnerability is triggered by improper handling of memory during volume management operations, potentially involving numeric truncation (CWE-197) or out-of-bounds reads (CWE-125). To exploit this, an attacker requires physical access to the target machine and must already possess high-level administrative privileges (PR:H). Successful exploitation allows for arbitrary code execution at the kernel level, leading to full system compromise. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Published by Microsoft and NVD