Threat Advisory

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally (CVE-2026-56172)

HIGH CVSS 7.8 September 8, 2026

What happened

Recent advisories have identified a high-severity vulnerability, CVE-2026-56172, in the Windows VHD miniport driver. This flaw involves a use after free condition that can be exploited by an authorised attacker to elevate privileges locally. The vulnerability relies on the attacker already having access to the host or device, requiring no action from other users. Successful exploitation can lead to significant impacts, including the potential for further compromise of the affected system. The vulnerability has been assigned a CVSS score of 7.8, reflecting its critical implications when combined with the local access requirement.

Who is affected

Organisations running affected versions of Microsoft Windows that utilise the vulnerable VHD miniport driver are at risk. The attack conditions necessitate that the malicious actor has low-level access to the device, such as a low-privileged account, but no further user interaction is needed. While no specific product versions are specified here, any deployment integrating the impacted component should be audited for exposure. The vulnerability’s nature means that devices with local access to the host are potentially vulnerable to privilege escalation attacks.

Recommended actions

  1. Ensure that privilege hygiene is maintained across systems, controlling and limiting local user access to minimise opportunities for attackers to attain initial access.
  2. Implement device control measures to monitor and regulate the use of virtual hard disk components and related drivers.
  3. Enhance endpoint monitoring to detect suspicious activity, especially activities that may indicate privilege escalation attempts.
  4. Maintain a transparent security posture, including regular review of access privileges and minimisation of unnecessary local access points.
  5. Stay informed about updates from Microsoft regarding patches or mitigations for CVE-2026-56172 as they become available.

Indicators of compromise

Current information does not include specific indicators of compromise associated with this vulnerability.

Affected

Vendors: Microsoft

Products: Windows

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severityhigh
CVSS7.8
CVECVE-2026-56172
PublishedSeptember 8, 2026
VendorMicrosoft
ProductsWindows

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent