GHSA-6p5f-2v3f-hh8g · 严重度: high — Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker...
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
结论预警: CVE-2026-40407 综合评估为低风险(37.6/100):CVSS 技术影响为高级,利用概率偏低(EPSS 0.06%) 强制指令: 持续跟踪利用情报与 EPSS 变化,并适时复评优先级。
风险随态势动态变化;本站持续评估并同步更新本页展示内容。
EPSS 日更估计相对被利用可能性;百分位表示该 CVE 在已评分漏洞中的相对排名(越高表示相对更严重)。
| # | 日期 | 旧 EPSS 分数 | 新 EPSS 分数 | 变化(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-13 | 0.04% | 0.06% | +0.01% |
| 2 | 2026-05-13 | — | 0.04% | — |
完整 EPSS 历史 (共 2 条)
该 CVE 的 CVSS 指标。
| 底座分 | 版本 | 严重度 | 向量 | 可利用性 | 影响 | 分数来源 |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
GHSA-6p5f-2v3f-hh8g · 严重度: high — Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker...
| 厂商 | 产品 | 版本 | 原始 CPE |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9140 | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* |
| microsoft | windows_10_1607 | < 10.0.14393.9140 | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* |
| microsoft | windows_10_1809 | < 10.0.17763.8755 | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* |
| microsoft | windows_10_1809 | < 10.0.17763.8755 | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* |
| microsoft | windows_10_21h2 | < 10.0.19044.7291 | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
| microsoft | windows_10_21h2 | < 10.0.19044.7291 | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* |
| microsoft | windows_10_21h2 | < 10.0.19044.7291 | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
| microsoft | windows_10_22h2 | < 10.0.19045.7291 | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:* |
| microsoft | windows_10_22h2 | < 10.0.19045.7291 | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* |
| microsoft | windows_10_22h2 | < 10.0.19045.7291 | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:* |
| microsoft | windows_11_23h2 | < 10.0.22631.7079 | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* |
| microsoft | windows_11_23h2 | < 10.0.22631.7079 | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* |
| microsoft | windows_11_24h2 | < 10.0.26100.8390 | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* |
| microsoft | windows_11_24h2 | < 10.0.26100.8390 | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* |
| microsoft | windows_11_25h2 | < 10.0.26200.8390 | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* |
| microsoft | windows_11_25h2 | < 10.0.26200.8390 | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* |
| microsoft | windows_11_26h1 | < 10.0.28000.2113 | cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* |
| microsoft | windows_11_26h1 | < 10.0.28000.2113 | cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:* |
| microsoft | windows_server_2012 | — | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
| microsoft | windows_server_2012 | r2 | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
| microsoft | windows_server_2016 | < 10.0.14393.9140 | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
| microsoft | windows_server_2019 | < 10.0.17763.8755 | cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* |
| microsoft | windows_server_2022 | < 10.0.20348.5074 | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.2330 | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* |
| microsoft | windows_server_2025 | < 10.0.26100.32772 | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
| URL | 标签 |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407 | Vendor Advisory |