Executive brief
Windows iSCSI Target Service is a component that manages storage area network (SAN) connectivity for enterprises. A heap buffer overflow vulnerability in this service allows an attacker on the network to execute malicious code with system privileges, potentially compromising the entire server and any data stored on connected storage devices.
Technical details
A heap-based buffer overflow exists in the Windows iSCSI Target Service that processes iSCSI protocol messages. The vulnerability allows an unauthenticated attacker on the network to send a specially crafted iSCSI packet that triggers the overflow, overwriting adjacent heap memory and achieving arbitrary code execution. Attack requires network access to the iSCSI service port but no authentication or user interaction. Successful exploitation grants the attacker system-level code execution on the affected server. A security patch from Microsoft is expected to address this issue.
Affected products
- Microsoft Windows iSCSI Target Service
Timeline
- 2026-08-11: disclosed