CVE-2026-78454
Windows CD-ROM Driver Information Disclosure Vulnerability
Description
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
In plain language
AI Act nowThis Windows-only flaw can expose sensitive information to someone who already has access to your device; most small businesses should treat it as a patch-now item, but it’s not a typical remote attack.
CVE-2026-78454 is an information disclosure in the Windows CD-ROM driver caused by an out-of-bounds read, where an authorized attacker can read more data than intended on the affected Windows versions.
What to do now
- Check whether your Windows 10, Windows 11, Windows Server 2016, or Windows Server 2019 system has been updated past the fixed versions listed by Microsoft for CVE-2026-78454.
- Apply the available Microsoft update(s) for CVE-2026-78454 from the Microsoft Update Guide.
- If you can’t patch right away, restrict who can log onto and run actions on the affected machines (reduce “authorized attacker” access) until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-78454 and every CVE in our database. Create a free account — no credit card required.
Create Free Account