Junglewise Threat Intelligence

CVE-2026-42828: Microsoft Windows Projected File System Filter Driver privilege escalation

CVE-2026-42828 · Severity: high · CVSS 7.8 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability exists in a Windows component that manages how the operating system handles virtualized files and directories. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete disruption of the affected machine.

Technical details

A buffer over-read vulnerability (CWE-126) exists within the Windows Projected File System (ProjFS) Filter Driver. The flaw is triggered when the driver incorrectly handles memory boundaries during read operations, potentially allowing an attacker to access sensitive information or corrupt system memory. To exploit this, an attacker must first have local execution capabilities on the target system with low-level user privileges. Successful exploitation enables the attacker to elevate their privileges to SYSTEM level, granting full control over the host. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Windows Projected File System Filter Driver

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References