Impact
A heap‑based buffer overflow in the Windows iSCSI Target Service permits an attacker who can reach the service over the network to execute arbitrary code with system privileges. The flaw arises when the service parses incoming iSCSI commands and does not properly validate the size of the payload before copying it to a heap buffer. Successful exploitation could allow the attacker to take complete control of the affected host, steal data, or spread laterally, underscoring the severity of the vulnerability.
Affected Systems
Microsoft Windows 10 Version 1607 and Version 1809, Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025 including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely but still possible. The vulnerability is not yet listed in CISA’s KEV catalog, implying limited known exploitation to date. The likely attack vector is remote network access to the iSCSI Target Service; an attacker would need to send a specially crafted iSCSI request to trigger the heap overflow. Once executed, the code runs with the privileges of the service process, granting full control of the machine.
OpenCVE Enrichment