Junglewise Threat Intelligence

CVE-2026-40404: Microsoft Windows privilege escalation in UDFS driver

CVE-2026-40404 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows driver responsible for reading Universal Disk Format (UDF) files, which are commonly used on optical media like DVDs and Blu-rays. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.

Technical details

An elevation of privilege vulnerability exists in the Microsoft Windows Universal Disk Format File System Driver (UDFS). The flaw is rooted in a heap-based buffer overflow (CWE-122) and a numeric truncation error (CWE-197) within the driver component. To exploit this, an attacker would first need to log on to the system. They could then run a specially crafted application designed to exploit the vulnerability and take control of the affected system, escalating privileges from a standard user to SYSTEM. The attack vector is local, requiring no user interaction. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References