Impact
A heap‑based buffer overflow in the Windows Storage Port Driver allows an authorized local attacker to elevate privileges. The vulnerability stems from improper bounds checking and an integer calculation error that lets the attacker overwrite critical memory structures, leading to execution with SYSTEM level rights. This privilege escalation could enable the attacker to install software, modify configurations, or gain full control of the compromised machine.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; and Windows Server builds 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations for the specified server editions. All these operating systems contain the Storage Port Driver in a vulnerable state.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity with potential for privilege escalation when an attacker already holds a local account. EPSS is not available, and the vulnerability is not presently listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. The attack vector is local; the attacker must authenticate or otherwise obtain local access. However, because the flaw enables escalation to SYSTEM level, the impact is significant, and the risk is high if the environment is not patched.
OpenCVE Enrichment