CVE-2026-62699 — Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
Executive Summary
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
Overview
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Remote Code Execution 5101650 Base: 6.8 Temporal: 5.9 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Remote Code Execution 5101650 Base: 6.8 Temporal: 5.9 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Remote Code Execution 5101650 Base: 6.8 Temporal: 5.9 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Remote Code Execution 5101650 Base: 6.8 Temporal: 5.9 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 | 5120386 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5120386 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120386 |
Monthly Rollup | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Integer overflow (CWE-190) leading to a heap-based buffer overflow (CWE-122) in the Windows UDF file system driver udfs.sys volume-structure parsing, code execution via a malicious UDF disc (physical attack, AV:P). When mounting a UDF volume, udfs.sys reads on-disk volume-descriptor structures and, in UdfQueryOnDiskVolInfo / UdfUpdateVolumeStructures, computes a pool allocation size from an attacker-controlled count field taken from the disc (size = count << 3, i.e. count * 8, where count is *(uint*)(desc+0x48)). PRE: that size computation was not range-checked, so a large on-disk count makes the 32-bit size calculation wrap (integer overflow), yielding an undersized heap allocation that is then filled from the on-disk data - a heap buffer overflow. Because UDF volume mount runs in the kernel and is triggered by inserting/mounting a crafted UDF disc, this is a code-execution primitive (Microsoft classifies it RCE via physical attack). Diff of udfs.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_2661530937, the size derived from the on-disk count is now bounded before use - the 64-bit product (count << 3) is checked to be below 0x100000000 (and related descriptor sizes are validated) so the allocation size can no longer wrap, closing the integer-overflow-to-heap-overflow. UdfUpdateVcbPhase0 / UdfVerifyVolume / UdfQueryFreeBlocksAndNWA were updated under the same gate.
| Function | Address | Change | Note |
|---|---|---|---|
UdfQueryOnDiskVolInfo |
code change |
code (allocation size from on-disk count now overflow-checked, CFR-gated) | Post (Feature_2661530937): pcVar11 = (count /*(uint*)(desc+0x48)*/ << 3); if (pcVar11 < 0x100000000) { ...validate descriptor sizes... } - bounds the 64-bit size so count*8 cannot wrap into an undersized allocation. |
UdfUpdateVolumeStructures |
code change |
code (descriptor size handling hardened, CFR-gated) | Reworked reads of the on-disk partition/volume descriptor (stride 0x38 entries) with the gated size validation (e.g. local_58 = count<<3) before allocating/reading. |
UdfUpdateVcbPhase0 / UdfVerifyVolume / UdfQueryFreeBlocksAndNWA |
code change |
code (mount-path validation updated) | Volume-mount / verify path updated in concert under Feature_2661530937. |
Feature_2661530937 |
gate |
added (CFR gate) | CFR flag gating the on-disk size-overflow validation; the original unchecked size computation still ships when disabled. |
Attack Path
A malicious UDF disc supplies a large descriptor count so the mount allocation size wraps and the heap buffer overflows
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Thanatos Tian (HKPolyU) & npc0vo & @2st__ with Diffract