# CVE-2026-62751 — Windows Projected File System `prjflt.sys` Unbounded Length in Backing-Layer Negative-Path-Cache Lookup → Integer Overflow

---

## Summary

| | |
|---|---|
| **Product** | Windows — `prjflt.sys` (Windows Projected File System / ProjFS minifilter) |
| **CVE ID** | CVE-2026-62751 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.8 / 6.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-190: Integer Overflow or Wraparound |
| **Delivery** | Local — ProjFS placeholder / virtualization operations |
| **KB / Fixed build** | KB5121003 — `prjflt.sys` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `prjflt.sys` 10.0.26100.8972 — SHA256 `bc4f4ca80b6867fc0f9c284c5628fc03dd8e266d7dea8ff3927a6db700448bef` |
| **Post-patch binary** | `prjflt.sys` 10.0.26100.9168 — SHA256 `63f1efd43e8084f9c83034b193f32b483927ddbe3b5d3ec7f308cab4e945201a` |
| **Feature flag** | `Feature_66039097` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`prjflt.sys` is the Windows Projected File System (ProjFS) minifilter. To speed up
lookups for files that do not exist in the backing layer, ProjFS maintains a
**negative path cache**. `PrjfLookupEntryBackingLayerNegativePathCache` consults that
cache for a path/entry whose length is derived from attacker-influenced ProjFS
operations (placeholder/virtualization requests).

---

## Vulnerability Summary

Pre-patch, the path/entry **length** used by the negative-path-cache lookup was
consumed **without an upper bound**. A length larger than `0xffff` overflows a
subsequent size/index computation (integer overflow, CWE-190), leading to memory
corruption in the kernel minifilter. Because `prjflt` runs in the kernel and the
lookup is reachable by a local user through ProjFS operations, the overflow is a
local elevation-of-privilege primitive to SYSTEM (per the MSRC FAQ).

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`): drive ProjFS placeholder /
  virtualization operations that reach the backing-layer negative-path-cache lookup.
- Supply an entry/path whose length exceeds `0xffff`.
- Result: the size/index computation wraps in the kernel minifilter.

---

## Vulnerability Details

### Root Cause

The path/entry length used in the negative-path-cache lookup was not bounded before
being used to size or index a computation, so an over-large length wrapped.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_66039097`, `PrjfLookupEntryBackingLayerNegativePathCache` now
**rejects a length exceeding `0xffff`** before using it:

```c
// PrjfLookupEntryBackingLayerNegativePathCache (10.0.26100.9168) — PATCHED (from our diff)
if (Feature_66039097__private_IsEnabledDeviceUsageNoInline()) {
    if (0xffff < uVar2) {          // *** upper bound on the length ***
        // log + fail; do not use the length
    }
}
```

The related `PrjfProcessPrjReparsePointBounce` path additionally validates the
reparse-buffer length (`*param_5 < 0x14`) before `PrjfPartiallyExpandDirectory`. With
the length bounded, the size/index computation can no longer overflow, closing the
integer overflow.

### Patch Completeness Assessment

**CFR-gated behind `Feature_66039097`.** The length bound runs only when the flag is
enabled; the original unbounded use still ships when disabled. Verify
`Feature_66039097` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** ProjFS operations presenting entries/paths with anomalously large
lengths (> 65535); integer-overflow / pool-corruption bugchecks in
`prjflt!PrjfLookupEntryBackingLayerNegativePathCache` on unpatched/flag-disabled
builds.

**Config.** The fix is CFR-gated — confirm `Feature_66039097` is enabled.

---

## References

- MSRC advisory — CVE-2026-62751 (Windows Projected File System Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/prjflt_sys-cve-2026-62751-ghidriff.md`
