Executive brief
Windows iSCSI is a storage networking protocol used to transmit SCSI commands over IP networks, commonly in enterprise data center environments. A heap-based buffer overflow in this component allows an authorized network attacker to execute arbitrary code with system privileges, potentially compromising the integrity and availability of storage infrastructure and the servers connected to it.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows iSCSI implementation that permits remote code execution. The vulnerability requires network access and valid iSCSI authentication credentials; an attacker with such access can send a specially crafted iSCSI command to trigger the overflow and execute arbitrary code with the privileges of the iSCSI service. The root cause appears to be insufficient bounds checking in iSCSI packet handling. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed