Executive brief
Windows CD-ROM Driver contains an out-of-bounds read vulnerability that allows a local, authenticated attacker to elevate their privileges on a system. This could enable an attacker with limited account access to gain higher privileges and take control of the affected computer, potentially leading to data theft, malware installation, or system compromise.
Technical details
The vulnerability is an out-of-bounds read in the Windows CD-ROM Driver, allowing a local, authenticated attacker to trigger the flaw. The attack vector requires local access and prior authentication on the system. By exploiting this out-of-bounds read, an attacker can escalate privileges from a limited user account to a higher privilege level. A patch is available through Microsoft Security Response Center. The vulnerability has not been observed in active exploitation in the wild at time of disclosure.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed