Overview
What is CVE-2026-72985?
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
Vulnerability intelligence
CVE-2026-72985 and is rated Medium severity with a CVSS score of 6.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.