Impact
A heap-based buffer overflow in the Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. This classic instance of CWE‑122 can corrupt heap structures and lead to arbitrary code execution. The impact includes remote code execution on the host running the iSCSI target, potentially giving attackers full control over that system.
Affected Systems
The flaw affects Microsoft Windows 10 Version 1607 and Version 1809, as well as Windows Server 2012 (including Server Core), Windows Server 2012 R2 (including Server Core), Windows Server 2016, Windows Server 2019 (including Server Core), Windows Server 2022 and Windows Server 2025 (including Server Core). Both 32‑bit and 64‑bit builds are impacted as indicated by the presence of x86, x64 and unspecified architectures in the CPE list.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not yet listed in the CISA KEV catalog. Based on the nature of the iSCSI Target Service, the attack vector is inferred to be network‑based, requiring an attacker to send specially crafted iSCSI traffic to a host with the target service enabled. The exploit does not currently require elevated privileges or authentication, as it can be triggered by any remote network host. Once triggered, the attacker can execute arbitrary code on the host, compromising the entire system hosting the iSCSI target.
OpenCVE Enrichment