Executive brief
Microsoft's Virtual Hard Disk (VHD) Miniport Driver, a critical storage component that manages virtual disk operations in Windows, contains a null pointer dereference vulnerability. A local attacker with limited privileges can exploit this flaw to crash the system or cause significant service interruption, impacting system availability and requiring administrative intervention to restore operations.
Technical details
A null pointer dereference vulnerability exists in the Virtual Hard Disk (VHD) Miniport Driver, a Windows kernel-mode storage driver responsible for managing virtual disk I/O operations. The vulnerability is triggered when the driver attempts to dereference a null pointer under specific conditions, likely during abnormal disk state transitions or malformed I/O requests. Exploitation requires local system access (authenticated or physical access in some Windows configurations) and results in a kernel panic or denial of service. The attack vector is local, and the vulnerability has not been observed in active exploitation as of the published date.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed