Executive brief
The Windows CD-ROM Driver contains an out-of-bounds read vulnerability that allows an authorized local user to read sensitive information from system memory. While this requires existing access to the device, a successful exploit could expose confidential data such as encryption keys, credentials, or other protected system information, potentially compromising overall system security.
Technical details
An out-of-bounds read vulnerability exists in the Windows CD-ROM Driver, a kernel-mode component responsible for managing CD/DVD media access. The vulnerability allows an authenticated local attacker to craft a malicious request that reads memory beyond the intended buffer boundaries. Exploitation requires local system access and does not involve network transmission. A successful attack discloses sensitive kernel-mode memory contents. Microsoft has released or will release a patch; users should apply the security update referenced in the Microsoft Security Response Center advisory.
Affected products
- Microsoft Windows CD-ROM Driver
Timeline
- 2026-09-08: disclosed