Junglewise Threat Intelligence

CVE-2026-40409: Microsoft Windows privilege escalation in UDFS driver

CVE-2026-40409 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows driver responsible for reading Universal Disk Format (UDF) files, which are commonly used on optical media like DVDs and Blu-rays. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.

Technical details

An elevation of privilege vulnerability exists in the Microsoft Windows Universal Disk Format File System Driver (UDFS) due to a numeric truncation error (CWE-197). The flaw allows a local attacker with low privileges to execute code with SYSTEM-level permissions. Exploitation typically requires the attacker to run a specially crafted application on the target system. The vulnerability is triggered during the processing of UDF file system structures where improper handling of integer sizes leads to memory corruption or logic errors. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD

References