Junglewise Threat Intelligence

CVE-2026-77492: Microsoft Storage Port Driver out-of-bounds read

CVE-2026-77492 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft's Storage Port Driver, a core Windows component responsible for managing storage device communication, contains an out-of-bounds read vulnerability. An authorized local attacker could exploit this to read sensitive information from system memory, potentially exposing credentials, encryption keys, or other confidential data. This requires existing local access to the system.

Technical details

The vulnerability is an out-of-bounds read flaw in Microsoft's Storage Port Driver (storport.sys). The attack requires local system access and valid user credentials, and allows an attacker to read memory beyond allocated buffer boundaries. Successful exploitation could disclose sensitive kernel or system data resident in memory. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows Storage Port Driver

Timeline

  • 2026-09-08: disclosed

References