Impact
The Windows iSCSI implementation contains a heap‑based buffer overflow that permits an authorized attacker to execute arbitrary code on the target system. This flaw allows malicious code to be loaded and run within the context of system services handling iSCSI traffic, thereby compromising confidentiality, integrity, and availability. The weakness is classified as CWE-122.
Affected Systems
The issue affects a broad range of Microsoft Windows operating systems, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1, 23H2, 26H1), and Windows Server editions from 2012 through 2025. All listed versions rely on the built‑in iSCSI storage support and are therefore vulnerable when the iSCSI target service is present and reachable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, though the EPSS score of 0.00913 (<1%) indicates a very low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog, but it requires network access to an authenticated iSCSI target. An attacker with the ability to connect to the target can trigger the overflow, which may lead to full system compromise. The lack of public exploit evidence suggests that this vulnerability remains a significant but controlled risk for organizations that expose iSCSI services over internal or external networks.
OpenCVE Enrichment