Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | |
| Title | Windows Projected File System Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft windows 10 1809 Microsoft windows 10 21h2 Microsoft windows 10 22h2 Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2025 |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows 10 1809 Microsoft windows 10 21h2 Microsoft windows 10 22h2 Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2025 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-06-09T17:49:33.746Z
Reserved: 2026-04-30T14:51:12.704Z
Link: CVE-2026-42837
No data.
Status : Received
Published: 2026-06-09T17:17:09.453
Modified: 2026-06-09T17:17:09.453
Link: CVE-2026-42837
No data.
OpenCVE Enrichment
No data.
Weaknesses