CVE-2026-23672 — Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5078938 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5078938 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5078752 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5078752 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5078885 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5078883 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5078883 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8037 10.0.26100.7979 Yes None Windows 11 Version 24H2 for x64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8037 10.0.26100.7979 Yes None Windows 11 Version 25H2 for ARM systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8037 10.0.26200.7979 Yes None Windows 11 Version 25H2 for x64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8037 10.0.26200.7979 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5079466 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5079466 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 | 5078775 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5078775 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5078774 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5078774 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5078938 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5078938 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5078752 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5078752 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5078766 (Security Update) 5078737 (Security Hotpatch Update) Important Elevation of Privilege 5075906 5075943 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4893 10.0.20348.4830 Yes No None Windows Server 2022 (Server Core installation) 5078766 (Security Update) 5078737 (Security Hotpatch Update) Important Elevation of Privilege 5075906 5075943 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4893 10.0.20348.4830 Yes No None Windows Server 2022, 23H2 Edition (Server Core installation) | 5078734 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5078938 |
Security Update | Yes |
5078752 |
Security Update | Yes |
5078885 |
Security Update | Yes |
5078883 |
Security Update | Yes |
5079466 |
Security Update | Yes |
5078775 |
Monthly Rollup | Yes |
5078774 |
Monthly Rollup | Yes |
5078734 |
Security Update | Yes |
Patch Diff
Out-of-bounds read (CWE-125) in the Windows UDF file-system driver udfs.sys, local EoP. The set-information handlers UdfCommonSetInfo (FilePositionInformation), UdfSetEndOfFileInfo (class 0x934) and UdfSetAllocationInfo (class 2356) accept signed 64-bit file position/EOF/allocation values from user mode without validating that they are non-negative. A negative _LARGE_INTEGER value passes the existing class checks and is used in kernel size/offset arithmetic as an out-of-range magnitude, driving an OOB read. Diff of udfs.sys 10.0.26100.4652 (no check) -> .8036 confirms the fix: a 'value >= 0' check is added to all three classes, gated behind CFR flag Feature_3887279419, returning STATUS_INVALID_PARAMETER (0xC000000D) for negative values (UdfSetAllocationInfo: `v9 != 2356 || feature && a5->QuadPart < 0`; UdfSetEndOfFileInfo: `v9 != 0x934 || feature && a5->QuadPart < 0`; UdfCommonSetInfo: accept CurrentByteOffset only if feature-disabled or position >= 0). The .8036->.8328 pair shows no change because the gated code was already present in .8036; the March KB5079473 (.8037) ships it enabled. Note: our diff shows Feature_3887279419, differing from the circulated screenshots' Feature_4155714875 (build/arch difference); the >=0 / STATUS_INVALID_PARAMETER logic is identical.
| Function | Address | Change | Note |
|---|---|---|---|
UdfSetAllocationInfo |
code change |
code (negative-value check added, CFR-gated) | Post: `if (v9 != 2356 || (Feature_3887279419 && a5->QuadPart < 0)) return 0xC000000D;` before UdfSetFileAllocationSize. Pre: only `v9 != 2356` checked, negative allocation accepted. |
UdfSetEndOfFileInfo |
code change |
code (negative-value check added, CFR-gated) | Post: `if (v9 != 0x934 || (Feature_3887279419 && a5->QuadPart < 0)) return 0xC000000D;`. Pre: only class checked. |
UdfCommonSetInfo |
code change |
code (negative FilePositionInformation rejected, CFR-gated) | Post: sets FileObject->CurrentByteOffset.QuadPart only if feature disabled or position (*p_Type) >= 0, else STATUS_INVALID_PARAMETER. Pre: set the byte offset from the user value unconditionally. |
Feature_3887279419 |
gate |
added (CFR gate) | CFR flag gating the >=0 negative-value validation across the three UDFS set-info classes. |
Attack Path
A negative 64-bit file position/EOF/allocation value bypasses UDFS validation and drives an out-of-bounds read
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
Microsoft