Executive brief
Windows Encrypting File System (EFS) is a built-in feature that protects sensitive files on Windows computers through encryption. A heap-based buffer overflow vulnerability in EFS allows an authorized user with local access to elevate their privileges to a higher level of system access, potentially enabling them to modify protected files, install malware, or compromise the entire system.
Technical details
A heap-based buffer overflow exists in the Windows Encrypting File System (EFS) implementation. The vulnerability requires that an attacker already have authorized local access to the system. By exploiting this buffer overflow, an attacker can corrupt heap memory and achieve local privilege escalation. The attack vector is local and requires prior authentication; the attacker can then execute code with elevated privileges. Microsoft has issued a security update to patch this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed