Impact
An out‑of‑bounds read vulnerability exists in the Windows Storage Spaces Controller that allows a local attacker with authorized access to read memory beyond intended bounds. This flaw can be exploited to elevate privileges on the affected system. The weakness is identified as a buffer overread.
Affected Systems
Microsoft Windows 11 versions 22H3, 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2022, Windows Server 2025 and their Server Core installations are impacted by this elevation of privilege flaw.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate to high severity. No EPSS score is supplied and the vulnerability is not listed in the CISA KEV catalog, so the probability of exploitation is uncertain. The local attack vector requires an authorized user, making the risk noteworthy for environments that use Storage Spaces. Prompt patching is advised to mitigate the risk.
OpenCVE Enrichment