Executive brief
A heap-based buffer overflow vulnerability exists in the Windows Storage Port Driver, a core Windows component responsible for managing storage device communication. An authenticated local attacker can exploit this flaw to execute arbitrary code with elevated system privileges, potentially compromising the entire machine and all data on it.
Technical details
The vulnerability is a heap-based buffer overflow in the Windows Storage Port Driver that can be triggered by an authenticated local user. The attack vector requires local access and prior authorization on the system. By sending a specially crafted request to the Storage Port Driver, an attacker can overflow a heap buffer, overwrite adjacent memory structures, and achieve arbitrary code execution with kernel-level privileges. This enables complete system compromise. Microsoft has released security updates to patch this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed