Description
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the Windows Container Isolation FS Filter Driver (unionfs.sys). An attacker with authorized local access can exploit this overflow to gain higher privileges on the host. The flaw is a classic memory corruption issue classified as CWE‑122, enabling an attacker to bypass normal privilege boundaries.

Affected Systems

The vulnerability affects Microsoft Windows 11 26H1 on x64 systems. The affected component is the unionfs.sys driver used for container isolation within this Windows release.

Risk and Exploitability

The CVSS base score of 7.8 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests that, at the time of analysis, the probability of exploitation is low but not zero. The vulnerability is not listed in CISA KEV, reducing the immediate operational awareness for most organizations. The attack vector is inferred to be local, requiring authentication or the ability to deploy a malicious container or process that interacts with the unionfs.sys component. Once exploited, the attacker can elevate privileges to the host level and potentially compromise other containers or the entire system.

Generated by OpenCVE AI on August 12, 2026 at 16:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 cumulative update that contains a fix for the unionfs.sys buffer overflow
  • Limit the use of Windows containers to trusted sources and restrict user privileges that can create containers
  • Disable the UnionFS driver when it is not needed by editing the appropriate registry or group policy settings
  • Monitor Microsoft security advisories for future patches and support updates

Generated by OpenCVE AI on August 12, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 26h1

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
Title Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:09.418Z

Reserved: 2026-07-14T21:04:04.256Z

Link: CVE-2026-62772

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:26.179Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:29.930

Modified: 2026-08-13T15:57:49.547

Link: CVE-2026-62772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:21:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow