You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 25174
About this tag
CVE-2026-25174 is a local privilege escalation vulnerability in the Windows exFAT file system driver, caused by an out-of-bounds read. Published on March 10, 2026, it carries a CVSS v3.1 base score of 7.8. Microsoft states that an authorized local attacker can exploit this flaw to elevate privileges to a higher account on affected systems. Discussions on WindowsForum.com cover the technical details of the out-of-bounds read, the affected Windows versions, and mitigation steps such as applying the latest security patches. This tag aggregates community threads and updates related to CVE-2026-25174, helping users stay informed about the vulnerability and its impact on Windows systems.
Microsoft has cataloged a new local elevation-of-privilege (EoP) vulnerability in the Windows Extensible File Allocation Table (exFAT) implementation — tracked as CVE-2026-25174 — an out‑of‑bounds read that Microsoft says can allow an authorized local attacker to escalate privileges to a higher...