Impact
Stack-based buffer overflow in the Windows Storage Spaces Controller allows an attacker who already has user‑level access to gain elevated privileges on the local machine. The flaw occurs when the controller processes oversized input before copying it into a stack buffer, enabling the overwrite of return addresses or other control data. An attacker could use this to execute code with higher rights, potentially modifying system files, installing malware, or escalating to full system compromise, depending on the privileges held after escalation.
Affected Systems
The vulnerability affects Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from version 23H2 through 26H1, and Windows Server releases 2012 through 2025, including Server Core installations. All listed editions of these OS versions that include the Windows Storage Spaces component are potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.8 indicating moderate to high severity. The EPSS score is not available, and the vulnerability is not reported in the CISA KEV catalog. The flaw is local and requires that the attacker already has authenticated user access to the target system; no remote attack surface is described. Given the local requirement, exploitation likelihood depends on the presence of privileged local users or services that the attacker can manipulate, making the risk moderate for systems exposed to potentially malicious local accounts.
OpenCVE Enrichment