Junglewise Threat Intelligence

CVE-2026-69384: Microsoft Windows Virtual Hard Disk Miniport Driver null pointer dereference

CVE-2026-69384 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft's Virtual Hard Disk (VHD) Miniport Driver, a critical storage component that manages virtual disk operations in Windows, contains a null pointer dereference vulnerability. A local attacker with limited privileges can exploit this flaw to crash the system or cause significant service interruption, impacting system availability and requiring administrative intervention to restore operations.

Technical details

A null pointer dereference vulnerability exists in the Virtual Hard Disk (VHD) Miniport Driver, a Windows kernel-mode storage driver responsible for managing virtual disk I/O operations. The vulnerability is triggered when the driver attempts to dereference a null pointer under specific conditions, likely during abnormal disk state transitions or malformed I/O requests. Exploitation requires local system access (authenticated or physical access in some Windows configurations) and results in a kernel panic or denial of service. The attack vector is local, and the vulnerability has not been observed in active exploitation as of the published date.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats