Important CVSS 7 EPSS 0.00246 🔬 Patch diffed 2026-08 archive

Executive Summary

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

Overview

7
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00246 — 0.16012 percentile
NVD CVSS 7 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.1

EPSS Score

0.00246
probability of exploitation in the next 30 days
0.16012 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 5120386 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5120386 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5120238 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Elevation of Privilege Yes

Patches

7 patches
Article Type Restart
5120418 Security Update Yes
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes
5120386 Monthly Rollup Yes
5120385 Monthly Rollup Yes

Patch Diff

ghidriff · luafv.sys (KB5121003)

Heap-based buffer overflow (CWE-122) via a race in the Windows LUA File Virtualization filter driver luafv.sys FileId-table node update, local EoP to SYSTEM (AC:H race). LUAFV virtualizes file access for legacy (LUA) apps and maintains a table of FileId nodes that cache per-file state including a path/name UNICODE_STRING (stored at node+0x50). UpdateTableNode refreshes a node from current file information (GetFileInformation) and, on failure, removed the node. PRE: the node-update path was insufficiently synchronized against concurrent update/removal of the same node, so a racing operation could update or reallocate the node's cached buffer while another path used it - a race leading to a heap buffer overflow of the node's allocation. Because luafv runs in the kernel and the virtualization path is reachable by a local user, and exploitation requires winning the race (AC:H), the overflow is a local EoP-to-SYSTEM primitive. Diff of luafv.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_285200698, UpdateTableNode adds a name-match check (RtlCompareUnicodeString against the node name at +0x50) and gates the RemoveFileIdTableNode call so a node is not removed/reused out from under a concurrent update, and routes the node allocation through the LuafvAllocatePool wrapper instead of raw ExAllocatePool2. Note: UpdateTableNode is confirmed code-changed under Feature_285200698 with the added name-match/gated-removal/allocator changes; the exact overflowing write is not cleanly isolable in this race-hardening restructure, so the mechanism is stated per the CWE-122 + AC:H classification and the observed changes.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
UpdateTableNode code change code (race-hardened FileId-table node update, CFR-gated) Pre: node update/removal on the FileId table node (name at +0x50) insufficiently synchronized -> racing update/realloc heap overflow. Post (Feature_285200698): adds RtlCompareUnicodeString name-match against node+0x50, gates the RemoveFileIdTableNode call, and allocates via LuafvAllocatePool instead of ExAllocatePool2.
LuafvAllocatePool call change now used for node allocation UpdateTableNode now routes the node allocation through the LuafvAllocatePool wrapper (replacing a direct ExAllocatePool2).
RemoveFileIdTableNode call change invocation gated Its removal call from UpdateTableNode is now conditioned under Feature_285200698 to avoid removing a node concurrently in use.
Feature_285200698 gate added (CFR gate) CFR flag gating the race-hardened node update; the original path still ships when disabled. (Feature_3287483706 / Feature_3614170424 also present in this update.)
View full diff report View RCA report

Attack Path

A concurrent update of a LUAFV FileId-table node races the node's removal/reallocation, overflowing its cached buffer

Attack path for CVE-2026-50472 A concurrent update of a LUAFV FileId-table node races the node's removal/reallocation, overflowing its cached buffer 01 — ENTRY Local user drives LUAFV file virtualization to update a FileId-table node luafv.sys UpdateTableNode refreshes a node caching a file's name/state (name at +0x50). AV:L/PR:L/AC:H (race). 02 — CONTROLLED INPUT Issues concurrent operations on the same node Update and removal/reallocation of the node run without adequate synchronization. 03 — MISSING CHECK A racing update/realloc overflows the node's cached buffer (CWE-122) The node buffer is written/reused with mismatched state while another path holds it. 04 — PATH Heap corruption in the kernel LUAFV node allocation Controlling the overflowed node data influences kernel state. 05 — PRIMITIVE Kernel heap overflow -> EoP to SYSTEM The Aug 2026 fix (Feature_285200698) adds a name-match check, gates node removal, and uses the LuafvAllocatePool wrapper.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments