Executive brief
The Windows Storage Port Driver, a core component responsible for managing storage device communication, contains a memory read vulnerability that could allow an attacker with physical access to a system to read sensitive data from memory. This could expose confidential information stored in RAM, including passwords, encryption keys, or other protected data.
Technical details
An out-of-bounds read vulnerability exists in the Windows Storage Port Driver, a kernel-level component that handles storage device I/O operations. The vulnerability allows an attacker with physical access to craft a malicious storage request that causes the driver to read memory beyond allocated boundaries, potentially disclosing sensitive information. The attack requires direct physical access to the system and does not require authentication or network connectivity. A successful exploit could lead to information disclosure of data residing in kernel memory.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed