Important CVSS 7.8 EPSS 0.00311 🔬 Patch diffed 2026-08 archive

Executive Summary

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00311 — 0.23682 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00311
probability of exploitation in the next 30 days
0.23682 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

10 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes

Patches

3 patches
Article Type Restart
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes

Patch Diff

ghidriff · prjflt.sys (KB5121003)

Integer overflow (CWE-190) in the Windows Projected File System minifilter prjflt.sys backing-layer negative-path-cache lookup, local EoP to SYSTEM. ProjFS caches negative path lookups against the backing layer; PrjfLookupEntryBackingLayerNegativePathCache processes a path/entry whose length (uVar2) is derived from attacker-influenced ProjFS operations. PRE: that length was used without an upper bound, so a value larger than 0xffff overflows a subsequent size/index computation (integer overflow), leading to memory corruption in the kernel minifilter. Because prjflt runs in the kernel and the lookup is reachable by a local user via ProjFS placeholder/virtualization operations, the overflow is a local EoP-to-SYSTEM primitive. Diff of prjflt.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_66039097, PrjfLookupEntryBackingLayerNegativePathCache now rejects a length exceeding 0xffff (if (0xffff < uVar2) -> error) before using it; the related PrjfProcessPrjReparsePointBounce path adds a reparse-buffer length check (*param_5 < 0x14) before PrjfPartiallyExpandDirectory. Note: Feature_66039097 gates the 0xffff length bound in PrjfLookupEntryBackingLayerNegativePathCache; several other ProjFS feature flags are present in this update.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
PrjfLookupEntryBackingLayerNegativePathCache code change code (length bounded to 0xffff before use, CFR-gated) Pre: entry/path length (uVar2) used without an upper bound -> value > 0xffff overflows a size/index computation. Post (Feature_66039097): if (0xffff < uVar2) reject before use.
PrjfProcessPrjReparsePointBounce code change code (reparse-buffer length validated) Adds a length check (*param_5 < 0x14) around the reparse-point processing / PrjfPartiallyExpandDirectory path.
Feature_66039097 gate added (CFR gate) CFR flag gating the 0xffff length bound; the original unbounded length use still ships when disabled.
View full diff report View RCA report

Attack Path

An unbounded path/entry length in the ProjFS negative-path-cache lookup overflows a size computation

Attack path for CVE-2026-62751 An unbounded path/entry length in the ProjFS negative-path-cache lookup overflows a size computation 01 — ENTRY Local user drives ProjFS placeholder/virtualization operations prjflt.sys PrjfLookupEntryBackingLayerNegativePathCache checks the backing layer for a path. AV:L/PR:L/AC:L. 02 — CONTROLLED INPUT Supplies an entry/path whose length exceeds 0xffff The length (uVar2) is attacker-influenced and used to size/index a computation. 03 — MISSING CHECK Length used without an upper bound -> integer overflow (CWE-190) A value > 0xffff wraps the subsequent size/index calculation. 04 — PATH Undersized/wrapped computation corrupts kernel memory The overflowed size drives a bad allocation/index in the minifilter. 05 — PRIMITIVE Kernel memory corruption -> EoP to SYSTEM The Aug 2026 fix (Feature_66039097) rejects length > 0xffff before use.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments

Anonymous
Zeze
Thanatos Tian (HKPolyU) & wgg with Diffract