Executive brief
Windows exFAT file system contains an out-of-bounds read vulnerability that allows an authorized network attacker to elevate their privileges. This could enable an attacker with initial access to gain administrative control over affected Windows systems, compromising system security and enabling further attacks.
Technical details
An out-of-bounds read vulnerability exists in the Windows exFAT file system driver. An authorized attacker on the network can exploit this flaw to read memory outside intended boundaries, which can be leveraged to escalate privileges. The vulnerability requires the attacker to already have some form of network access or authentication, but does not require local code execution as a prerequisite. A successful exploit would allow privilege elevation to a higher permission level. Microsoft has released or is expected to release security patches through their regular update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed