Impact
A heap-based buffer overflow exists in the Windows Storage Spaces Controller, which may be triggered by an authorized local attacker to execute arbitrary code. This flaw allows the attacker to run code with the privileges of the Storage Spaces Controller process, potentially escalating privileges and compromising the integrity of the system. The underlying weakness is identified as CWE-122.
Affected Systems
The vulnerability affects Microsoft Windows 10 (versions 1607, 1809, 21H2, and 22H2), Windows 11 (versions 23H2, 24H2, 25H2, and 26H1), and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. All systems that run the Storage Spaces Controller component, regardless of CPU architecture, are susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. No EPSS value is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authenticated access, making it a concern for environments where privileged users may be compromised. The risk remains significant for organizations that enable Storage Spaces and rely on default update channels.
OpenCVE Enrichment