Executive brief
Windows iSCSI Target Service is a network storage protocol service used by organizations to enable storage area networking. A heap buffer overflow vulnerability allows an attacker on the network to execute arbitrary code with elevated privileges, potentially compromising entire systems and any data they access.
Technical details
The vulnerability is a heap-based buffer overflow in the Windows iSCSI Target Service. The flaw permits an unauthenticated attacker on the network to send crafted iSCSI protocol packets that trigger the buffer overflow, leading to arbitrary code execution. The attack requires network connectivity to the iSCSI service (typically port 3260) but no prior authentication or user interaction. A successful exploit would grant the attacker system-level code execution on the affected host.
Affected products
- Microsoft Windows iSCSI Target Service
Timeline
- 2026-08-11: disclosed