Impact
An error in buffer size calculation in the Windows iSCSI stack permits an attacker to corrupt memory and execute arbitrary code. The flaw is a classic buffer overflow (CWE-131) that can be triggered over the network without authentication. Successful exploitation would grant the attacker full control over the affected Windows system, enabling arbitrary code execution, data exfiltration, and lateral movement. The vulnerability is purely remote and requires only network access to an iSCSI target, making it highly attractive for attackers seeking privileged execution.
Affected Systems
Vendors and products impacted include Microsoft Windows 10 releases starting from version 1607 through 22H2, Windows 11 releases 23H2 up to 26H1, and Windows Server editions from 2012 through 2025. These variants encompass both 32‑bit and 64‑bit builds, as well as ARM‑64 for newer Windows 11 releases. The vulnerability is present in all enumerated builds that support the iSCSI protocol.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity Remote Exploit. Aggregate threat information shows that Microsoft has not listed this vulnerability in the KEV catalog, and no EPSS score has been published, which could indicate limited public exploitation data. Based on the description, the likely attack vector is a remote network connection to an iSCSI target that accepts connections from an untrusted or compromised host. Although no specific public exploits are known, the conditions are typical for a remote code execution attack, granting complete system compromise if successful.
OpenCVE Enrichment