Executive brief
A security vulnerability exists in Windows Storage Spaces Direct, a technology used to create highly available and scalable storage using industry-standard servers. An attacker with physical access to the hardware could exploit this flaw to execute unauthorized code on the system. This could lead to a complete loss of confidentiality, integrity, and availability of the affected server and its stored data.
Technical details
This vulnerability is classified as an integer overflow or wraparound (CWE-190) which leads to a heap-based buffer overflow (CWE-122) within the Windows Storage Spaces Direct component. The attack vector is restricted to physical access (AV:P), meaning an attacker must have hands-on access to the target hardware to trigger the flaw. Successful exploitation allows for arbitrary code execution with high privileges, impacting the system's confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Version 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 R2 All versions
- Microsoft Windows Storage Spaces Direct All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory