CVE-2026-40409
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS
7.8
Alto
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-197
0.3%EPSS · 30 días0.3%
2026-08-112026-09-07
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-87529——
———Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)9hCVE-2026-785128.8 ALT—
———Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.6hCVE-2026-698227.8 ALT—
———Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.6hCVE-2026-695787.0 ALT—
———Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.6hCVE-2026-695357.8 ALT—
———Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.5hCVE-2026-695128.0 ALT—
———Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.5h