Executive brief
Windows Storage Management Provider, a component responsible for managing storage devices and volumes on Windows systems, contains a stack-based buffer overflow vulnerability. An authorized local attacker can exploit this flaw to gain elevated privileges on affected machines, potentially gaining administrative access to the system.
Technical details
A stack-based buffer overflow exists in the Windows Storage Management Provider component, allowing an authenticated local attacker to elevate privileges. The vulnerability requires local access and prior authorization on the target system. Exploitation enables privilege escalation from an authorized user context to higher privilege levels (likely SYSTEM). Microsoft has released patches to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed