Executive brief
Windows Storage Spaces Controller is a Microsoft Windows system component that manages storage configurations and disk pooling. A use-after-free vulnerability in this component allows an authorized local user to escalate their privileges to system level, potentially compromising the entire computer.
Technical details
A use-after-free vulnerability exists in the Windows Storage Spaces Controller component. The vulnerability requires an attacker to have valid local authentication credentials (authorized user account) to trigger the flaw. By exploiting the use-after-free condition, an attacker can execute arbitrary code with elevated system privileges. This is a local privilege escalation vulnerability that does not require network access or user interaction beyond having initial local account access. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Windows Storage Spaces Controller <UNKNOWN>
Timeline
- 2026-09-08: disclosed