CVE-2026-69582: Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
Other sources
Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the listed Microsoft Windows client or server products are in scope. Exploitation requires local access and authorization, so it is most relevant where a low-privileged user or a process running with limited privileges can execute code on the system.
What level of access does an attacker need to exploit it?
An attacker must already be authorized on the target and have local access. No user interaction is required once those conditions are met.
What could an attacker gain through successful exploitation?
Successful exploitation allows elevation of privilege and is rated for high impact to confidentiality, integrity, and availability. This could allow the attacker to operate with greater privileges than initially granted.