Important CVSS 7.8 EPSS 0.00353 🔬 Patch diffed 2026-03 archive

Executive Summary

None

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Exploitation Unlikely
MS Exploit Likelihood
Category Elevation of Privilege
Released Mar 10 2026
Last Updated Mar 10 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00353 — 0.28318 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00353
probability of exploitation in the next 30 days
0.28318 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

23 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5078938 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5078938 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5078752 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5078752 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5078885 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5078883 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5078883 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8037 10.0.26100.7979 Yes None Windows 11 Version 24H2 for x64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8037 10.0.26100.7979 Yes None Windows 11 Version 25H2 for ARM systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8037 10.0.26200.7979 Yes None Windows 11 Version 25H2 for x64-based Systems 5079473 (Security Update) 5079420 (Security Hotpatch Update) Important Elevation of Privilege 5077181 5077212 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8037 10.0.26200.7979 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5079466 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5079466 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 5078775 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5078775 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5078774 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5078774 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5078938 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5078938 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5078752 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5078752 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5078766 (Security Update) 5078737 (Security Hotpatch Update) Important Elevation of Privilege 5075906 5075943 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4893 10.0.20348.4830 Yes No None Windows Server 2022 (Server Core installation) 5078766 (Security Update) 5078737 (Security Hotpatch Update) Important Elevation of Privilege 5075906 5075943 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4893 10.0.20348.4830 Yes No None Windows Server 2022, 23H2 Edition (Server Core installation) 5078734 (Security Update) Important Elevation of Privilege Yes

Patches

8 patches
Article Type Restart
5078938 Security Update Yes
5078752 Security Update Yes
5078885 Security Update Yes
5078883 Security Update Yes
5079466 Security Update Yes
5078775 Monthly Rollup Yes
5078774 Monthly Rollup Yes
5078734 Security Update Yes

Patch Diff

ghidriff · udfs.sys (KB5079473)

Out-of-bounds read (CWE-125) in the Windows UDF file-system driver udfs.sys, local EoP. The set-information handlers UdfCommonSetInfo (FilePositionInformation), UdfSetEndOfFileInfo (class 0x934) and UdfSetAllocationInfo (class 2356) accept signed 64-bit file position/EOF/allocation values from user mode without validating that they are non-negative. A negative _LARGE_INTEGER value passes the existing class checks and is used in kernel size/offset arithmetic as an out-of-range magnitude, driving an OOB read. Diff of udfs.sys 10.0.26100.4652 (no check) -> .8036 confirms the fix: a 'value >= 0' check is added to all three classes, gated behind CFR flag Feature_3887279419, returning STATUS_INVALID_PARAMETER (0xC000000D) for negative values (UdfSetAllocationInfo: `v9 != 2356 || feature && a5->QuadPart < 0`; UdfSetEndOfFileInfo: `v9 != 0x934 || feature && a5->QuadPart < 0`; UdfCommonSetInfo: accept CurrentByteOffset only if feature-disabled or position >= 0). The .8036->.8328 pair shows no change because the gated code was already present in .8036; the March KB5079473 (.8037) ships it enabled. Note: our diff shows Feature_3887279419, differing from the circulated screenshots' Feature_4155714875 (build/arch difference); the >=0 / STATUS_INVALID_PARAMETER logic is identical.

Pre-patch version 10.0.26100.4652 Download
Post-patch version 10.0.26100.8036 Download
Function Address Change Note
UdfSetAllocationInfo code change code (negative-value check added, CFR-gated) Post: `if (v9 != 2356 || (Feature_3887279419 && a5->QuadPart < 0)) return 0xC000000D;` before UdfSetFileAllocationSize. Pre: only `v9 != 2356` checked, negative allocation accepted.
UdfSetEndOfFileInfo code change code (negative-value check added, CFR-gated) Post: `if (v9 != 0x934 || (Feature_3887279419 && a5->QuadPart < 0)) return 0xC000000D;`. Pre: only class checked.
UdfCommonSetInfo code change code (negative FilePositionInformation rejected, CFR-gated) Post: sets FileObject->CurrentByteOffset.QuadPart only if feature disabled or position (*p_Type) >= 0, else STATUS_INVALID_PARAMETER. Pre: set the byte offset from the user value unconditionally.
Feature_3887279419 gate added (CFR gate) CFR flag gating the >=0 negative-value validation across the three UDFS set-info classes.
View full diff report View RCA report

Attack Path

A negative 64-bit file position/EOF/allocation value bypasses UDFS validation and drives an out-of-bounds read

Attack path for CVE-2026-23672 A negative 64-bit file position/EOF/allocation value bypasses UDFS validation and drives an out-of-bounds read 01 — ENTRY Local low-priv caller issues NtSetInformationFile on a UDFS file udfs.sys handles FilePosition/EndOfFile/Allocation set-info classes. AV:L/PR:L: any local user with a handle to a UDFS file/volume. 02 — CONTROLLED INPUT Supplies a NEGATIVE signed 64-bit value (position / EOF / allocation size) The value is a _LARGE_INTEGER; nothing rejected QuadPart < 0 pre-patch. 03 — PATH UdfCommonSetInfo / UdfSetEndOfFileInfo / UdfSetAllocationInfo accept the value The class check passes and the negative value flows into kernel size/offset arithmetic (e.g. FileObject->CurrentByteOffset, allocation size). 04 — MISSING CHECK No `>= 0` validation of the signed 64-bit value (CWE-125) The negative magnitude is interpreted as an out-of-range / wrapped offset or size, outside the valid bounds. 05 — PRIMITIVE Out-of-bounds kernel read -> information disclosure / instability -> EoP The driver reads outside the intended buffer/range. The Mar 2026 fix (Feature_3887279419) rejects negative values with STATUS_INVALID_PARAMETER in all three classes.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments

Microsoft