Executive brief
A security vulnerability exists in the Windows Storage Spaces driver, which manages how data is stored across multiple drives. An attacker with physical access to a computer could exploit this flaw to gain full control over the system. This could lead to the theft of sensitive data or the installation of malicious software, even if the attacker does not have an account on the machine.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists within the Windows Spaceport.sys driver, which is responsible for Storage Spaces functionality. The vulnerability is triggered via a physical attack vector, meaning an attacker must have physical access to the target hardware to exploit the flaw. Successful exploitation allows an unauthorized attacker to bypass security boundaries and elevate their privileges to a higher level, potentially gaining full SYSTEM access. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions including Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory