Impact
WinFsp through version 2.2.26215 contains a null pointer dereference in its kernel driver's Fast I/O device control handler, caused by an improper validation of the volume context before use. When triggered, an attacker can force the system to crash, resulting in an interruption of services and an unavailable file system. The flaw directly exposes the operating system kernel to a crash without denial of authentication or data disclosure.
Affected Systems
This vulnerability affects all installations of WinFsp up to and including version 2.2.26215. The affected components are the kernel driver and the Fast I/O device control interface. Users running earlier builds of WinFsp are also susceptible.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of 0.00116 indicates a very low probability of exploitation. The flaw is not yet listed in the CISA KEV catalog, but at least local, unprivileged users can exploit it by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests. A successful exploit results in a system crash, classifying it as a local denial of service. The risk therefore remains significant for environments where unprivileged users have access to the control device.
OpenCVE Enrichment