PT-2026-40209 · Unknown+1 · Volume Manager Extension Driver+1

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-40380

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Volume Manager Extension Driver (affected versions not specified)
Description A heap-based buffer overflow in the Volume Manager Extension Driver allows an authorized attacker to execute arbitrary code. This issue can be triggered via a physical attack or remotely, potentially affecting the entire system. A heap-based buffer overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, leading to memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Out of bounds Read

Heap Based Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-07123
CVE-2026-40380

Affected Products

Volume Manager Extension Driver
Windows