CVE-2026-68844
massHeap Buffer Overflow in Windows Storage Spaces Controller Enables Local Code Execution
CVE-2026-68844 is a heap-based buffer overflow (CWE-122) in the Windows Storage Spaces Controller, the Microsoft component that manages Storage Spaces storage pools. Per the CVSS vector (AV:L/AC:L/PR:L/UI:N), a local, authorized attacker with low privileges can trigger the overflow with no user interaction required; the published data does not describe the exact trigger or vulnerable code path. Successful exploitation allows the attacker to execute code on the affected host, with scoring indicating high impact to confidentiality, integrity, and availability. Any Windows system with the Storage Spaces controller present and enabled is affected, most notably Windows Server deployments using Storage Spaces, although the provided data lists no specific affected version ranges. There are no signs of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns roughly a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's fix for CVE-2026-68844 via the Windows monthly update as soon as it is published; no specific affected builds were provided in this data, so consult Microsoft's advisory for exact version mappings. Prioritize hosts where Storage Spaces is actually enabled (e.g., check Get-StoragePool or the Storage Spaces feature state), especially shared or multi-user storage servers. Until patched, restrict low-privileged local logon on storage hosts and monitor for anomalous local process creation.
| Microsoft Windows Storage Spaces Controller | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.