CVE-2026-26184 Overview
CVE-2026-26184 is a buffer over-read vulnerability in the Windows Projected File System (ProjFS) that enables an authorized attacker to elevate privileges locally. This vulnerability affects the Windows kernel component responsible for managing projected file system operations, allowing attackers who have already gained initial access to a system to escalate their privileges and potentially gain complete control over the affected machine.
Critical Impact
Local privilege escalation through buffer over-read in Windows Projected File System could allow attackers to gain elevated system privileges and execute arbitrary code with kernel-level access.
Affected Products
- Windows Projected File System (ProjFS) component
- Windows systems with ProjFS enabled or in use
- Systems running virtualized file system operations
Discovery Timeline
- April 14, 2026 - CVE-2026-26184 published to NVD
- April 14, 2026 - Last updated in NVD database
Technical Details for CVE-2026-26184
Vulnerability Analysis
This vulnerability is classified as CWE-126: Buffer Over-read, which occurs when a program reads data past the end of an intended buffer boundary. In the context of Windows Projected File System, this over-read condition can be exploited by a local attacker to access sensitive memory contents that could facilitate privilege escalation.
The Windows Projected File System is a kernel-mode component that allows user-mode file system providers to project hierarchical data from a backing data store into the file system. When processing certain malformed or specially crafted requests, the ProjFS driver fails to properly validate buffer boundaries, resulting in the over-read condition.
An attacker with local access and low-level privileges can exploit this vulnerability without requiring any user interaction. Successful exploitation can lead to complete compromise of confidentiality, integrity, and availability of the affected system.
Root Cause
The root cause of CVE-2026-26184 lies in improper buffer boundary validation within the Windows Projected File System driver. When handling file system operations, the driver reads beyond the allocated buffer boundary due to insufficient length checks. This CWE-126 (Buffer Over-read) condition allows an attacker to potentially access sensitive kernel memory contents, which can be leveraged to bypass security controls and escalate privileges.
Attack Vector
The attack vector for this vulnerability is local, meaning an attacker must have existing access to the target system. The exploitation sequence involves:
- An attacker with low-privilege local access crafts a malicious request targeting the ProjFS component
- The crafted request triggers the buffer over-read condition in the kernel driver
- The attacker can read sensitive memory contents beyond the intended buffer boundary
- Information disclosed through the over-read is used to facilitate privilege escalation
- The attacker gains elevated privileges on the system
The vulnerability requires no user interaction, making it particularly dangerous in scenarios where an attacker has already achieved initial foothold on a system through other means. The information disclosed through the buffer over-read can include kernel memory addresses, security tokens, or other sensitive data that assists in further exploitation.
For detailed technical information, refer to the Microsoft CVE-2026-26184 Advisory.
Detection Methods for CVE-2026-26184
Indicators of Compromise
- Anomalous access patterns to Windows Projected File System components or PrjFlt.sys driver
- Unexpected privilege escalation events on systems with ProjFS enabled
- Kernel memory access violations or crash dumps related to ProjFS operations
- Suspicious local user activity attempting to interact with projected file system functionality
Detection Strategies
- Monitor for unusual system calls targeting the Windows Projected File System driver
- Implement kernel-level monitoring to detect abnormal memory access patterns
- Deploy endpoint detection solutions capable of identifying privilege escalation attempts
- Audit Event Log entries for security-relevant events associated with local privilege changes
Monitoring Recommendations
- Enable detailed Windows Security Event logging, particularly for privilege use (Event ID 4673, 4674)
- Monitor for process creation events where child processes run with higher privileges than parent
- Implement file integrity monitoring on critical system components including ProjFS-related binaries
- Deploy SentinelOne agents with behavioral AI to detect exploitation attempts in real-time
How to Mitigate CVE-2026-26184
Immediate Actions Required
- Apply the latest Microsoft security updates addressing CVE-2026-26184 as soon as available
- Review systems to identify where Windows Projected File System is enabled and assess exposure
- Implement the principle of least privilege to limit the impact of potential exploitation
- Ensure endpoint protection solutions are updated with the latest detection capabilities
Patch Information
Microsoft has released a security update addressing this vulnerability. Organizations should consult the Microsoft CVE-2026-26184 Advisory for specific patch details and affected product versions.
Apply patches through standard Windows Update mechanisms or enterprise deployment tools such as Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager. Prioritize patching for systems where ProjFS is actively used or enabled.
Workarounds
- If ProjFS is not required, consider disabling the Windows Projected File System feature until patches can be applied
- Restrict local access to systems where ProjFS is critical to reduce the attack surface
- Implement application whitelisting to prevent unauthorized applications from interacting with ProjFS components
- Segment networks to limit lateral movement opportunities for attackers who may have achieved initial access
# Check if Windows Projected File System is enabled
sc query prjflt
# Disable ProjFS if not required (run as Administrator)
sc config prjflt start= disabled
sc stop prjflt
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.


