Executive brief
Windows iSCSI Target Service is a Windows component that manages iSCSI storage connections. A null pointer dereference vulnerability allows a network attacker to crash the service and disrupt storage connectivity for affected systems without requiring authentication.
Technical details
This is a null pointer dereference vulnerability in Windows iSCSI Target Service that can be triggered over the network. The vulnerability requires no authentication and can be exploited by sending a specially crafted network request to the iSCSI service. An attacker can cause a denial of service by crashing the service, disrupting iSCSI storage access for dependent applications and systems. Patches are expected to be available from Microsoft.
Affected products
- Microsoft Windows iSCSI Target Service <UNKNOWN>
Timeline
- 2026-08-11: disclosed