Executive brief
The Volume Manager Driver is a Windows system component responsible for managing disk storage and volumes. A heap-based buffer overflow in this driver can be exploited by an authorized local user to execute code with elevated privileges, potentially gaining full control of the system.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Volume Manager Driver that can be triggered by an authorized local attacker to achieve privilege escalation. The vulnerability is triggered through local access and requires the attacker to already have user-level privileges on the system. Successful exploitation allows an attacker to execute arbitrary code with SYSTEM-level privileges, leading to complete system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Windows Volume Manager Driver <UNKNOWN>
Timeline
- 2026-09-08: disclosed