Junglewise Threat Intelligence

CVE-2026-72985: Microsoft Windows Volume Shadow Copy heap buffer overflow

CVE-2026-72985 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Executive brief

Windows Volume Shadow Copy is a system component that creates backup copies of files and volumes. A heap-based buffer overflow vulnerability in this component could allow an attacker with physical access to a system to gain elevated privileges and take full control of the machine.

Technical details

A heap-based buffer overflow exists in Windows Volume Shadow Copy, a core system component responsible for creating point-in-time copies of data. The vulnerability is triggered through a physical attack vector, likely involving direct access to system hardware or local boot mechanisms. An authenticated or local attacker can exploit this flaw to overwrite heap memory, potentially leading to code execution with elevated system privileges. A patch is expected to be available through Microsoft Security Updates.

Affected products

  • Microsoft Windows Volume Shadow Copy <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References