Heap-Based Buffer Overflow in Windows Common Log File System Driver by Microsoft
CVE-2026-40407
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40407?
A heap-based buffer overflow vulnerability exists within the Windows Common Log File System Driver. An authorized attacker could exploit this flaw to elevate their local privileges, potentially allowing unauthorized actions on the affected system. Microsoft has provided a patch to mitigate this risk, underscoring the importance of applying updates promptly.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291