Executive brief
A memory handling flaw in Microsoft Windows' SCSI storage driver can allow an attacker on the network to read sensitive information from the system's memory. This could expose confidential data stored on the affected computer or connected storage devices without requiring user interaction or special permissions.
Technical details
An integer underflow vulnerability exists in the Microsoft Windows SCSI Class System File driver. The flaw allows a network-based attacker to craft malicious SCSI protocol messages that trigger memory disclosure. The vulnerability does not require authentication or user interaction. Successful exploitation results in information disclosure over the network; remote code execution is not possible through this vector alone.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed