Executive brief
Windows Storage Spaces Controller is a system component that manages storage pooling and virtual disk management on Windows servers and workstations. An authorized attacker can exploit an out-of-bounds read vulnerability to access sensitive information stored in memory, potentially exposing configuration data or other confidential system details.
Technical details
This vulnerability is an out-of-bounds read in the Windows Storage Spaces Controller, allowing disclosure of information from memory regions that should not be accessible. The attack requires local access and the attacker must be authorized (authenticated) on the system. An attacker with these preconditions can read memory beyond intended buffer boundaries, potentially exposing sensitive data such as encryption keys, system secrets, or other protected information. A security update is available from Microsoft to remediate this issue.
Affected products
- Microsoft Windows Storage Spaces Controller
Timeline
- 2026-09-08: disclosed