Impact
The vulnerability is a heap-based buffer overflow (CWE-122) in the Windows Storage Spaces Controller. An attacker who has local access to a system can exploit this flaw to execute arbitrary code within the context of the Service, resulting in complete control over the affected machine. The flaw does not provide remote or privilege escalation beyond what an attacker already possesses locally.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025—including their Core installations. Any system running these releases with the Storage Spaces Controller enabled is potentially vulnerable.
Risk and Exploitability
The CVSS V3 score of 7.8 indicates a high severity local code execution risk. However, the EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting lower exploitation activity. Exploitation requires that the attacker have physical or authorized local presence. In environments where privileged users can be compromised, or where users have elevated permissions, the risk becomes significant. The attack vector is local, and the vulnerability cannot be exploited remotely without additional compromise or exploitation of other flaws.
OpenCVE Enrichment