Description
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a heap‑based buffer overflow in the Windows Storage component that allows an attacker with local access to elevate privileges. The overflow can be triggered by sending data that causes an internal limit to be exceeded, enabling the attacker to gain administrative rights on the affected machine. This elevation compromises confidentiality, integrity, and availability by permitting the attacker to install malware, modify configuration, or exfiltrate data. The weakness is classified as CWE‑122, reflecting improper handling of untrusted input during memory allocation.

Affected Systems

Affected Microsoft Windows versions include Windows 11 23H2, 24H2, 25H2, 26H1, and the 23H2 arm64 build, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation). These versions are identified for both ARM64 and x64 architectures where applicable.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity. The EPSS value is unavailable, so the current likelihood of exploitation remains uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local; an attacker must already authenticate or otherwise execute code on the target system to exploit the overflow. Precise memory offsets are required, which limits widespread ease of exploitation. Nonetheless, once the overflow is triggered the attacker gains administrative privileges, making the issue critical to remediate as soon as possible.

Generated by OpenCVE AI on August 12, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates for Windows 11 and Windows Server 2022/2025 to patch the storage component flaw.
  • Enable Windows Defender Exploit Guard and Controlled Folder Access to provide runtime protection against local privilege escalation attempts.
  • Enforce least privilege for local user accounts and disable unnecessary services or features that could be leveraged by an attacker with local access.

Generated by OpenCVE AI on August 12, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Title Windows Storage Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:48.684Z

Reserved: 2026-07-14T20:56:21.890Z

Link: CVE-2026-62695

cve-icon Vulnrichment

Updated: 2026-08-11T19:47:11.810Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:18.993

Modified: 2026-08-13T14:46:30.427

Link: CVE-2026-62695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:22:15Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow