Description
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

WinFsp through version 2.2.26215 contains a null pointer dereference in its kernel driver's Fast I/O device control handler, caused by an improper validation of the volume context before use. When triggered, an attacker can force the system to crash, resulting in an interruption of services and an unavailable file system. The flaw directly exposes the operating system kernel to a crash without denial of authentication or data disclosure.

Affected Systems

This vulnerability affects all installations of WinFsp up to and including version 2.2.26215. The affected components are the kernel driver and the Fast I/O device control interface. Users running earlier builds of WinFsp are also susceptible.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, and the EPSS score of 0.00116 indicates a very low probability of exploitation. The flaw is not yet listed in the CISA KEV catalog, but at least local, unprivileged users can exploit it by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests. A successful exploit results in a system crash, classifying it as a local denial of service. The risk therefore remains significant for environments where unprivileged users have access to the control device.

Generated by OpenCVE AI on September 19, 2026 at 18:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WinFsp to a version newer than 2.2.26215 that resolves the null pointer dereference.
  • Reconfigure the WinFsp control device so that only privileged users can access it, reducing the attack surface for local users.
  • Monitor system logs for unexpected kernel crashes or service interruptions, and configure alerts to detect symptoms of the vulnerable behavior.

Generated by OpenCVE AI on September 19, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Winfsp
Winfsp winfsp
Vendors & Products Winfsp
Winfsp winfsp

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
Title WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:05.325Z

Reserved: 2026-09-18T14:39:01.816Z

Link: CVE-2026-93689

cve-icon Vulnrichment

Updated: 2026-09-18T16:18:40.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:15.837

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses