Junglewise Threat Intelligence

CVE-2026-56172: Microsoft Windows VHD miniport driver use-after-free privilege escalation

CVE-2026-56172 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows VHD (Virtual Hard Disk) miniport driver contains a use-after-free memory vulnerability that allows an authenticated local attacker to elevate privileges on affected systems. An attacker with local access can exploit this flaw to gain elevated system permissions, potentially compromising the entire machine.

Technical details

A use-after-free vulnerability exists in the Windows VHD miniport driver, which handles virtual hard disk operations at the system level. The vulnerability allows a local, authenticated attacker to trigger a condition where freed memory is accessed, leading to code execution with elevated privileges. The attack requires local access and valid credentials but does not require administrative privileges to initiate. Exploitation results in local privilege escalation to SYSTEM level. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats