Executive brief
Microsoft Windows SCSI Class System File contains a vulnerability that allows an attacker with physical access to a computer to elevate their privileges and gain elevated control of the system. This could enable unauthorized access to sensitive data or system administration capabilities on affected machines.
Technical details
An untrusted pointer dereference vulnerability exists in the Microsoft Windows SCSI Class System File, a core Windows component responsible for managing SCSI storage device communication. The vulnerability allows an attacker with physical access to the system to exploit the flaw and elevate privileges. This is a local privilege escalation attack that requires physical access to the device, making it a lower-impact but still significant vulnerability for shared systems or devices that may be physically compromised.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed