Junglewise Threat Intelligence

CVE-2026-42837: Microsoft Windows buffer over-read in Projected File System Filter Driver

CVE-2026-42837 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a Windows component responsible for managing virtualized file systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete disruption of the device's operations.

Technical details

A buffer over-read vulnerability (CWE-125) exists within the Windows Projected File System (ProjFS) Filter Driver. The flaw is triggered when the driver fails to properly validate the length of a buffer before performing a read operation. An attacker with low-privileged local access can exploit this by sending a specially crafted request to the driver, leading to an out-of-bounds memory access. Successful exploitation allows the attacker to execute code with elevated system privileges, bypassing standard security boundaries. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Not specified

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References