Executive brief
Windows Storage Spaces Controller is a Windows system component that manages disk storage configurations. A heap buffer overflow vulnerability allows a local user with administrative or elevated privileges to execute arbitrary code with system-level access, potentially compromising the entire Windows system.
Technical details
A heap-based buffer overflow exists in the Windows Storage Spaces Controller component. The vulnerability is triggered during local processing of specially crafted input, allowing an authenticated attacker with elevated privileges to overflow a heap buffer and achieve arbitrary code execution. The attack vector is local, requiring prior authorization and the ability to execute code on the target system. No public exploit code is currently known to be circulating. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched