Junglewise Threat Intelligence

CVE-2026-78452: Microsoft Windows SCSI Class System File out-of-bounds read

CVE-2026-78452 · Severity: medium · CVSS 4.6 · Published 2026-09-08

Executive brief

A flaw in Microsoft Windows' SCSI Class driver can leak sensitive information when an attacker with physical access to a system exploits an out-of-bounds memory read. This vulnerability could expose confidential data such as encryption keys or user credentials stored in memory, but requires the attacker to have direct hardware access to the affected machine.

Technical details

An out-of-bounds read vulnerability exists in the Microsoft Windows SCSI Class System File (likely Scsiport.sys or related kernel driver). The vulnerability is triggered through a malformed or specially crafted SCSI command that causes the driver to read memory beyond allocated buffer boundaries. The attack vector is physical—requiring direct access to hardware interfaces such as SCSI or SAS ports. An attacker can leverage this flaw to disclose kernel memory contents, potentially revealing sensitive data. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Multiple versions

Timeline

  • 2026-09-08: disclosed

References

Related threats