Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued a security update for CVE-2026-69582, titled Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability. The Important-rated flaw is a CWE-126 buffer over-read in the Windows Volume Manager Extension Driver.

Microsoft’s advisory states: “Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability: Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.” A successful attack could result in SYSTEM privileges, the highest privilege level on a Windows installation.

This is a local elevation-of-privilege issue, meaning an attacker must already be authorized on the device before attempting to exploit it. That does not make it a housekeeping item: privilege escalation flaws are a frequent second step after malware, a malicious user, or a compromised low-privilege account gains an initial foothold.

CVE-2026-69582 at a glance​

  • CVE: CVE-2026-69582
  • Title: Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
  • Severity: Important
  • CWE: CWE-126
  • CVSS base score: 7.8
  • CVSS temporal score: 6.8
  • CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • Vulnerability type: Buffer over-read
  • Impact: Elevation of privilege to SYSTEM
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes
  • Exploitation assessment: Exploitation Unlikely

The CVSS vector reflects a locally accessible flaw with low attack complexity, where an attacker needs low privileges but does not need a victim to click anything. The potential effect covers confidentiality, integrity, and availability, all rated High in the supplied vector. In plain English: the initial foothold is a requirement, but the prize is substantial.

Why SYSTEM-level elevation matters​

SYSTEM is not simply another administrator account. It is the security context used by core Windows components and services, with broad control over local system resources. If an authorized attacker successfully exploited this flaw, Microsoft says they could gain SYSTEM privileges.

For enterprises, that makes patching relevant to more than traditional endpoint security. Administrators should include this update in routine Windows client and server compliance checks, particularly on systems where multiple users, remote sessions, third-party applications, or service accounts can establish lower-privilege local access.

Affected Windows products and required updates​

Microsoft’s remediation is version-specific. Install the applicable KB and verify that the device reaches the corresponding fixed build.

Affected productRequired remediation
Windows 10 Version 1607 for 32-bit Systems (x86)For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1607 for x64-based SystemsFor Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1809 for 32-bit Systems (x86)For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 1809 for x64-based SystemsFor Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 21H2 for 32-bit Systems (x86)For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 21H2 for ARM64-based SystemsFor Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 21H2 for x64-based SystemsFor Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 22H2 for 32-bit Systems (x86)For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 10 Version 22H2 for ARM64-based SystemsFor Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 10 Version 22H2 for x64-based SystemsFor Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 11 Version 23H2 for ARM64-based SystemsFor Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
Windows 11 Version 23H2 for x64-based SystemsFor Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
Windows 11 Version 24H2 for ARM64-based SystemsFor Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
Windows 11 Version 24H2 for x64-based SystemsFor Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
Windows 11 Version 25H2 for ARM64-based SystemsFor Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
Windows 11 Version 25H2 for x64-based SystemsFor Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
Windows 11 Version 26H1 for ARM64-based SystemsFor Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows 11 version 26H1 for x64-based SystemsFor Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows Server 2012 (Server Core installation) (x64)For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 (x64)For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 R2 (Server Core installation) (x64)For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2012 R2 (x64)For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2016 (Server Core installation) (x64)For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2016 (x64)For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2019 (Server Core installation) (x64)For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2019 (x64)For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2022 (Server Core installation) (x64)For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2022 (x64)For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2025 (Server Core installation) (x64)For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Windows Server 2025 (x64)For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Practical patching advice​

For managed fleets, deploy the applicable cumulative update through the organization’s established servicing process, then use build reporting to confirm endpoints reached the fixed version. Build validation is worth doing because a successfully reported deployment is not always the same thing as a successfully restarted and serviced machine—Windows patching has always had a small talent for demanding proof of life.

For individual PCs, install the applicable Windows update and restart when prompted. The essential result is not merely that a KB appears in update history; it is that the device reaches the fixed build listed for its Windows release and processor architecture.

CVE-2026-69582 is assessed as Exploitation Unlikely, and Microsoft records Exploited: No. Nevertheless, the potential to turn authorized local access into SYSTEM control gives this vulnerability a clear operational priority: patch the affected Windows versions, confirm the target build, and keep ordinary-user and service-account privileges appropriately constrained.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com