Executive brief
A security vulnerability exists in the Windows Storage Spaces Controller, a component used by Windows to manage and group physical disks into virtual drives. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or the disruption of business operations.
Technical details
An integer overflow (CWE-190) exists within the Windows Storage Spaces Controller. The vulnerability is triggered when the component improperly handles specific integer calculations, leading to a wraparound condition. A locally authenticated attacker with low privileges can exploit this flaw by sending specially crafted requests to the controller. Successful exploitation allows the attacker to execute code with elevated system privileges, bypassing standard security boundaries. Microsoft has released security updates to address this issue; users should apply the latest Windows updates to mitigate the risk.
Affected products
- Microsoft Windows Storage Spaces Controller
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory