CVE-2026-40380 | Microsoft Windows up to Server 2025 Volume Manager Extension Driver heap-based overflow
A vulnerability described as problematic has been identified in Microsoft Windows. Affected is an unknown function of the component Volume Manager Extension Driver. The manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-40380. An attack on the physical device is feasible. There is not any exploit available.
Upgrading the affected component is recommended.