# CVE-2026-62699 — Windows UDF File System `udfs.sys` On-Disk Count Integer Overflow in Volume-Structure Parsing → Heap Buffer Overflow

---

## Summary

| | |
|---|---|
| **Product** | Windows — `udfs.sys` (Universal Disk Format file system driver) |
| **CVE ID** | CVE-2026-62699 |
| **Impact** | Remote Code Execution (kernel; via physical/mounted media) |
| **MSRC severity** | Important |
| **CVSS** | 6.8 / 5.9 — `CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-190: Integer Overflow → CWE-122: Heap-based Buffer Overflow |
| **Delivery** | Physical (`AV:P`) — inserting / mounting a crafted UDF disc/image |
| **KB / Fixed build** | KB5121003 — `udfs.sys` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `udfs.sys` 10.0.26100.8972 — SHA256 `8a29f2c834fb955f3813b0fea3d880a57a93866f439a890c18d0dfa45376491a` |
| **Post-patch binary** | `udfs.sys` 10.0.26100.9168 — SHA256 `8ac119f739b481d6e97ac332738436649ad1ac62bc82c5730b4ac93c0046a4a3` |
| **Feature flag** | `Feature_2661530937` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`udfs.sys` is the Windows Universal Disk Format (UDF) file system driver. When a UDF
volume is mounted, the driver reads the on-disk volume/partition descriptor
structures and builds its in-memory volume control block. `UdfMountVolume` →
`UdfUpdateVolumeStructures` → `UdfQueryOnDiskVolInfo` parse these descriptors and
allocate pool buffers sized from fields read directly off the disc.

---

## Vulnerability Summary

One of those allocations is sized from an attacker-controlled **count** field taken
from the on-disk descriptor (`count = *(uint *)(desc + 0x48)`), scaled by 8
(`count << 3`) to size an array. Pre-patch this size computation was **not
range-checked**, so a large on-disk count causes the size calculation to **wrap**
(integer overflow, CWE-190), yielding an **undersized** heap/pool allocation. The
mount code then fills that buffer from the on-disk data, overflowing it — a kernel
heap buffer overflow (CWE-122). Because the parse happens in the kernel at mount
time and is driven entirely by the contents of a crafted UDF disc/image, Microsoft
classifies this as remote code execution via a physical attack (`AV:P`): an attacker
supplies the malicious medium and the victim mounts it.

---

## Prerequisites and Constraints

- Physical (`AV:P`), no privileges/interaction beyond mounting (`PR:N`, `UI:N`): the
  victim inserts or mounts a crafted UDF disc or image.
- The disc declares an oversized descriptor count so `count << 3` overflows.
- Result: an undersized kernel allocation is overflowed with on-disk data during
  mount.

---

## Vulnerability Details

### Root Cause

The pool allocation size derived from an on-disk descriptor count (`count * 8`) was
used without checking that the product fits, so a crafted count wrapped the size and
produced an allocation smaller than the data subsequently written into it.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_2661530937`, the size derived from the on-disk count is now
**bounded before use** — the 64-bit product is required to be below `0x100000000`
(so the value cannot wrap when used as a 32-bit size) and related descriptor sizes
are validated:

```c
// UdfQueryOnDiskVolInfo (10.0.26100.9168) — PATCHED, feature-enabled branch (from our diff)
if (Feature_2661530937__private_IsEnabledDeviceUsageNoInline()) {
    pcVar11 = (char *)((ulonglong)*(uint *)(desc + 0x48) << 3);   // count * 8, 64-bit
    if (pcVar11 < (char *)0x100000000) {                          // *** overflow guard ***
        // validate descriptor sizes (uVar7 bounds, page-rounded length) then proceed
        ...
    }
}
```

`UdfUpdateVolumeStructures` applies the same gated size validation before its
descriptor reads/allocations, and `UdfUpdateVcbPhase0` / `UdfVerifyVolume` /
`UdfQueryFreeBlocksAndNWA` were updated in concert. With the size bounded, the
count-derived allocation can no longer wrap, closing the overflow.

### Patch Completeness Assessment

**CFR-gated behind `Feature_2661530937`.** The size-overflow validation runs only
when the flag is enabled; the original unchecked computation still ships when
disabled. Verify `Feature_2661530937` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Mounting UDF media with anomalous/oversized volume-descriptor count
fields; heap/pool-overflow bugchecks in `udfs!UdfQueryOnDiskVolInfo` /
`UdfUpdateVolumeStructures` during mount on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_2661530937` is enabled.

---

## References

- MSRC advisory — CVE-2026-62699 (Windows UDFS Remote Code Execution), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/udfs_sys-cve-2026-62699-ghidriff.md`
