Executive brief
WinFsp is an open-source tool used to create custom file systems for Windows. A security flaw in this software could allow a user with limited access to gain full system-level control over the computer. This could lead to unauthorized access to sensitive data or the ability to disrupt system operations.
Technical details
An integer overflow vulnerability (CWE-190) exists in WinFsp versions 2.2.26112 and earlier. The flaw allows a local attacker with low privileges to trigger an overflow condition, potentially leading to a scope cross and full system-level access. The attack requires high complexity, likely due to specific timing or environmental conditions needed to trigger the overflow. A fix has been released in version 2.2B2 (v2.2.26183).
Affected products
- WinFsp WinFsp 2.2.26112 and lower
Timeline
- 2026-07-02: patched: Fix released in version 2.2B2 (v2.2.26183)
- 2026-07-13: advisory: CSA and NVD published advisory details