Executive brief
Windows iSCSI is a network protocol used for storage connectivity. An attacker can exploit an out-of-bounds read vulnerability in the iSCSI implementation to cause the system to crash or become unresponsive, disrupting network storage access and potentially causing service outages.
Technical details
An out-of-bounds read vulnerability exists in the Windows iSCSI subsystem that allows an unauthenticated attacker to send a specially crafted network packet triggering a memory access violation. The vulnerability can be exploited over the network without prior authentication. A successful exploit results in denial of service through system crash or hang, disrupting iSCSI storage connectivity and availability. A patch has been published by Microsoft to address this issue.
Affected products
- Microsoft Windows iSCSI <UNKNOWN>
Timeline
- 2026-09-08: disclosed