Junglewise Threat Intelligence

CVE-2026-69347: Microsoft Windows Fast FAT Driver heap buffer overflow

CVE-2026-69347 · Severity: high · CVSS 7.4 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Fast FAT Driver is a core component that handles the reading and writing of files on FAT-formatted storage devices. A heap-based buffer overflow in this driver allows a local attacker with limited privileges to execute arbitrary code with elevated permissions, potentially compromising the entire system and enabling malware installation or data theft.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Fast FAT Driver, a kernel-mode component responsible for FAT file system operations. The vulnerability is triggered through local file system operations; an attacker with local access can craft a malicious FAT file system or supply specially-formed input to cause a buffer overflow in heap memory. This allows code execution in kernel context, bypassing security boundaries and achieving full system compromise. The attack requires local access to the system but does not require administrative privileges as a precondition. Patches are expected to be available through Microsoft's standard security update process.

Affected products

  • Microsoft Windows Fast FAT Driver

Timeline

  • 2026-09-08: disclosed

References

Related threats