Description
Successful
exploitation of the integer overflow vulnerability could allow an attacker to
achieve system-level access to the affected software.
Published: 2026-07-13
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow within the WinFsp filesystem driver. When the integer value is corrupted, the driver can be manipulated to perform privileged operations, effectively granting an attacker system-level access to the affected software.

Affected Systems

The affected product is WinFsp. Any installed version that is not the latest release is potentially impacted. The advisory does not specify particular sub‑versions, but the recommendation is to upgrade to the most recent release.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% indicates a very low but nonzero chance of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the nature of WinFsp, a likely vector involves manipulating malicious filesystem operations. An attacker would need to craft input data that triggers the integer overflow in the vulnerable function.

Generated by OpenCVE AI on August 3, 2026 at 03:47 UTC.

Remediation

Vendor Solution

Users and administrators of affected product versions are advised to update to the latest version immediately.


OpenCVE Recommended Actions

  • Apply the latest WinFsp release immediately, following the vendor’s instructions.
  • If an update is not yet available or cannot be applied, enforce strict role‑based access controls to limit filesystem exposure.
  • Monitor Windows event logs for anomalous file system activity and consider isolating systems that use WinFsp on a separate network segment.

Generated by OpenCVE AI on August 3, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Enables System-Level Access

Wed, 29 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Enables System-Level Access

Sun, 26 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Allows System-Level Access

Thu, 23 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Allows System-Level Access

Mon, 20 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Enables System‑Level Access

Fri, 17 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Enables System‑Level Access

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Allows System‑Level Access

Mon, 13 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WinFsp Allows System‑Level Access

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Winfsp
Winfsp winfsp
Vendors & Products Winfsp
Winfsp winfsp

Mon, 13 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Description Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-07-13T15:45:56.103Z

Reserved: 2026-04-27T03:13:36.806Z

Link: CVE-2026-7162

cve-icon Vulnrichment

Updated: 2026-07-13T15:45:52.823Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:00:13Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound