
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23672 is an Elevation of Privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS) caused by an out-of-bounds read (CWE-125). It affects a broad range of Microsoft Windows versions, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2/2016/2019/2022/2025, and their Server Core variants. The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's Patch Tuesday release. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is rooted in an out-of-bounds read (CWE-125) in the Windows UDFS kernel driver's handling of disk operations. An attacker can craft a malicious UDF disk format to trigger the out-of-bounds read condition in the driver, which can then be leveraged to escalate privileges to SYSTEM level. Exploitation requires local access and low privileges, with no user interaction needed and no change in scope, making it straightforward for an authenticated local attacker to exploit. The attack is mapped to CAPEC-540 (Overread Buffers) (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who achieves SYSTEM privileges can read sensitive data, modify system configurations, install malware, create new accounts, and potentially use the compromised host as a pivot point for lateral movement within a network. The broad scope of affected products — spanning consumer and server Windows editions from 2012 through 2025 — significantly widens the potential attack surface (Microsoft MSRC).
.iso, .img, or UDF-formatted disk image files on the system; unexpected mounting of virtual disk devices by low-privileged user accounts.udfs.sys; kernel crash dumps (MEMORY.DMP) referencing udfs.sys in the stack trace.SYSTEM context spawned from a low-privileged user session; unusual use of diskpart, mountvol, or virtual disk management utilities by non-administrative accounts.Microsoft released patches on March 10, 2026, addressing this vulnerability across all affected platforms. Key patched builds include: Windows 10 1607/Server 2016 (10.0.14393.8957), Windows 10 1809/Server 2019 (10.0.17763.8511), Windows 10 21H2 (10.0.19044.7058), Windows 10 22H2 (10.0.19045.7058), Windows 11 23H2 (10.0.22631.6783), Windows Server 2022 (10.0.20348.4830), Windows Server 2022 23H2 (10.0.25398.2207), Windows 11 24H2 (10.0.26100.7979), Windows 11 25H2 (10.0.26200.7979), Windows Server 2025 (10.0.26100.32463), and Windows 11 26H1 (10.0.28000.1719). As a workaround where patching is not immediately possible, restrict local logon access to trusted users only and monitor for suspicious disk mount operations. Applying the March 2026 Patch Tuesday updates via Windows Update or WSUS is the recommended remediation (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by several security outlets. Rapid7, Sophos, Zero Day Initiative (ZDI), and Lansweeper all published Patch Tuesday summaries that included CVE-2026-23672 among the 78–83 vulnerabilities addressed that month. SANS ISC also noted the patch in its diary. No specific high-profile researcher commentary or significant social media discussion focused exclusively on this CVE has been observed, consistent with its lack of public PoC and no active exploitation (ZDI Blog, Rapid7 Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."