Junglewise Threat Intelligence

CVE-2026-78451: Microsoft Windows SCSI Class System File untrusted pointer dereference

CVE-2026-78451 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Executive brief

Microsoft Windows SCSI Class System File contains a vulnerability that allows an attacker with physical access to a computer to elevate their privileges and gain elevated control of the system. This could enable unauthorized access to sensitive data or system administration capabilities on affected machines.

Technical details

An untrusted pointer dereference vulnerability exists in the Microsoft Windows SCSI Class System File, a core Windows component responsible for managing SCSI storage device communication. The vulnerability allows an attacker with physical access to the system to exploit the flaw and elevate privileges. This is a local privilege escalation attack that requires physical access to the device, making it a lower-impact but still significant vulnerability for shared systems or devices that may be physically compromised.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats