Junglewise Threat Intelligence

CVE-2026-3006: WinFSP local privilege escalation via kernel heap overflow

CVE-2026-3006 · Severity: high · CVSS 7 · Published 2026-04-27

Technologies: WinFSP. Vendors: Red Hat, WinFSP.

Executive brief

WinFSP is a developer tool used to create custom file systems for Windows. A security flaw in this software could allow a person with limited access to a computer to gain full system-level control. This could lead to unauthorized access to sensitive data or the ability to disrupt operations on the affected machine.

Technical details

A race condition vulnerability (CWE-362/CWE-368) exists in WinFSP versions 2.1.25156 and earlier. The flaw occurs during concurrent execution or context switching, which can be exploited to trigger a kernel heap overflow. An attacker with local access and low privileges can leverage this to achieve local privilege escalation (LPE) and gain system-level permissions. The attack complexity is rated as high due to the timing requirements of the race condition. The issue is addressed in WinFSP version 2.2B1. Red Hat has also identified potential transitive impacts in products like Advanced Cluster Management for Kubernetes.

Affected products

  • WinFSP WinFSP 2.1.25156 and lower
  • Red Hat Advanced Cluster Management for Kubernetes 2 2

Timeline

  • 2026-04-22: patched: WinFSP 2026 Beta1 (v2.2B1) released with fix.
  • 2026-04-27: disclosed: Initial disclosure by CSA and Red Hat.
  • 2026-04-27: advisory: NVD record published.

References

Related threats