Junglewise Threat Intelligence

CVE-2026-78508: Microsoft Windows CD-ROM Driver out-of-bounds read

CVE-2026-78508 · Severity: medium · CVSS 4.6 · Published 2026-09-08

Executive brief

Windows CD-ROM Driver contains an out-of-bounds read vulnerability that allows an attacker with physical access to a system to read sensitive memory contents. An attacker would need to insert a specially crafted CD-ROM disc into an affected system to trigger the flaw, potentially exposing confidential data stored in memory. This risk is limited to environments where an attacker can physically interact with computer hardware.

Technical details

The vulnerability is an out-of-bounds read in the Windows CD-ROM Driver caused by insufficient bounds checking when processing disc data. An attacker with physical access can insert a malformed CD-ROM that triggers the flaw, causing the driver to read memory outside its intended boundaries. This allows disclosure of sensitive information from kernel or driver memory. The attack vector is physical, requiring direct access to the target machine's CD-ROM drive. No network or authentication bypass is required. Microsoft has published a security update to address this issue.

Affected products

  • Microsoft Windows CD-ROM Driver <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats