Junglewise Threat Intelligence

CVE-2026-34350: Microsoft Windows Storport Miniport Driver null pointer dereference

CVE-2026-34350 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Windows Storport Miniport Driver, a component responsible for managing storage devices, could allow a remote attacker to crash a system. By sending specially crafted data over the network, an attacker can trigger a system failure, leading to a denial of service. This could disrupt business operations and impact the availability of critical servers or workstations.

Technical details

A NULL pointer dereference (CWE-476) exists within the Windows Storport Miniport Driver. The vulnerability is reachable over the network and does not require administrative privileges, though it does require some level of user interaction according to the CVSS vector (UI:R). An attacker who successfully exploits this vulnerability can cause the affected system to crash (BSOD), resulting in a denial-of-service condition. Microsoft has released information regarding this vulnerability via CVE-2026-34350, and users are advised to apply the relevant security updates from the Microsoft Security Response Center.

Affected products

  • Microsoft Windows Storport Miniport Driver

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References