Junglewise Threat Intelligence

CVE-2026-69549: Microsoft Windows VHD Miniport Driver out-of-bounds read

CVE-2026-69549 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Virtual Hard Disk (VHD) Miniport Driver is a Windows component responsible for managing virtual disk access. An authorized attacker with local system access could exploit an out-of-bounds read vulnerability to elevate their privileges to a higher system level, potentially gaining full control of the affected computer.

Technical details

This vulnerability is an out-of-bounds read condition in the VHD Miniport Driver, a Windows kernel-mode driver responsible for virtual disk I/O operations. The flaw allows an authorized local attacker to read memory beyond the intended boundaries, which can be leveraged to disclose sensitive kernel data or craft a privilege escalation exploit. Attack preconditions include local system access and some level of authorization. The vulnerability enables local privilege escalation, potentially allowing an attacker to transition from a limited user or service account context to SYSTEM privileges. Microsoft has addressed this issue with security updates available through the standard patching process.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats