Executive brief
A flaw in Windows' CD-ROM driver could allow a user with local access to a system to escalate their privileges to a higher level of access. An attacker would need valid credentials or physical access to the machine to exploit this, but successful exploitation could give them complete control over the affected system.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows CD-ROM Driver that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access or valid credentials to trigger. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges, potentially leading to complete system compromise. The attack vector is local with medium complexity, as indicated by the CVSS score of 7.8.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed