Executive brief
Microsoft's Virtual Hard Disk (VHD) Miniport Driver, a storage component used to manage virtual disk operations on Windows systems, contains a heap-based buffer overflow vulnerability. An authorized attacker with local access could exploit this flaw to execute arbitrary code with elevated privileges, potentially compromising system security and data integrity.
Technical details
A heap-based buffer overflow exists in the Virtual Hard Disk (VHD) Miniport Driver, allowing an authorized local attacker to overflow heap memory during VHD processing. The vulnerability requires local access and some level of authorization to trigger. Successful exploitation enables arbitrary code execution with kernel-level privileges, giving an attacker control over the affected system. The flaw is well-documented with a CVSS score of 7.5, and patches are available through Microsoft security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed