CVE-2026-62772
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62772 is a Windows 11 bug that can let a local, low-privilege user gain full control of your computer, mainly if you use Windows containers; if you’re running Windows 11 with container isolation enabled, you should update.
CVE-2026-62772 is a local privilege escalation in the Windows Container Isolation FS Filter Driver (unionfs.sys) that allows an authorized low-privilege user to crash or corrupt memory via sending excessive data, leading to elevated privileges on Windows 11.
What to do now
- Check whether your Windows 11 device has Windows Container Isolation / unionfs.sys FS filter driver in use.
- Verify whether you are already on Windows 11 build 10.0.28000.2704 or later.
- Install the Microsoft August 2026 Patch Tuesday update that includes the fix for CVE-2026-62772.
- If you can’t patch right away, restrict who has local logon access to the affected machine and limit container usage until the update is applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62772 and every CVE in our database. Create a free account — no credit card required.
Create Free Account