Junglewise Threat Intelligence

CVE-2026-71341: Microsoft Windows Partition Management Driver out-of-bounds read

CVE-2026-71341 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

The Windows Partition Management Driver contains an out-of-bounds read vulnerability that allows an authorized local attacker to read sensitive information from system memory. This could expose confidential data such as encryption keys, credentials, or other sensitive details stored in memory. An attacker would need local access to the system to exploit this flaw.

Technical details

The vulnerability is an out-of-bounds read in the Windows Partition Management Driver that occurs when processing partition-related operations. The flaw allows an authenticated local attacker to read memory beyond intended boundaries, potentially disclosing sensitive information. This requires local system access and the attacker must have appropriate permissions to interact with the driver. While information disclosure may seem limited in scope, exposed data could include cryptographic material, credentials, or other secrets that further compromise system security. A patch from Microsoft is expected to be available through the standard Windows Update process.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed: CVE-2026-71341 published

References

Related threats