CVE-2026-62751 — Windows Projected File System Elevation of Privilege Vulnerability
Executive Summary
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
Patch Diff
Integer overflow (CWE-190) in the Windows Projected File System minifilter prjflt.sys backing-layer negative-path-cache lookup, local EoP to SYSTEM. ProjFS caches negative path lookups against the backing layer; PrjfLookupEntryBackingLayerNegativePathCache processes a path/entry whose length (uVar2) is derived from attacker-influenced ProjFS operations. PRE: that length was used without an upper bound, so a value larger than 0xffff overflows a subsequent size/index computation (integer overflow), leading to memory corruption in the kernel minifilter. Because prjflt runs in the kernel and the lookup is reachable by a local user via ProjFS placeholder/virtualization operations, the overflow is a local EoP-to-SYSTEM primitive. Diff of prjflt.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_66039097, PrjfLookupEntryBackingLayerNegativePathCache now rejects a length exceeding 0xffff (if (0xffff < uVar2) -> error) before using it; the related PrjfProcessPrjReparsePointBounce path adds a reparse-buffer length check (*param_5 < 0x14) before PrjfPartiallyExpandDirectory. Note: Feature_66039097 gates the 0xffff length bound in PrjfLookupEntryBackingLayerNegativePathCache; several other ProjFS feature flags are present in this update.
| Function | Address | Change | Note |
|---|---|---|---|
PrjfLookupEntryBackingLayerNegativePathCache |
code change |
code (length bounded to 0xffff before use, CFR-gated) | Pre: entry/path length (uVar2) used without an upper bound -> value > 0xffff overflows a size/index computation. Post (Feature_66039097): if (0xffff < uVar2) reject before use. |
PrjfProcessPrjReparsePointBounce |
code change |
code (reparse-buffer length validated) | Adds a length check (*param_5 < 0x14) around the reparse-point processing / PrjfPartiallyExpandDirectory path. |
Feature_66039097 |
gate |
added (CFR gate) | CFR flag gating the 0xffff length bound; the original unbounded length use still ships when disabled. |
Attack Path
An unbounded path/entry length in the ProjFS negative-path-cache lookup overflows a size computation
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Anonymous
Zeze
Thanatos Tian (HKPolyU) & wgg with Diffract