Junglewise Threat Intelligence

CVE-2026-72946: Microsoft Windows Storage Port Driver heap buffer overflow

CVE-2026-72946 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

The Windows Storage Port Driver, a core system component that manages communication with storage devices, contains a heap buffer overflow vulnerability. An authorized local attacker can exploit this flaw to execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

A heap-based buffer overflow exists in the Microsoft Windows Storage Port Driver, allowing a local authenticated attacker to trigger memory corruption through malformed input or requests to the driver. The vulnerability requires local access and may require specific preconditions to trigger reliably. Successful exploitation leads to privilege escalation, enabling the attacker to gain SYSTEM-level access and execute arbitrary code with kernel privileges. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats