CVE-2026-68877
massHeap-Based Buffer Overflow in Microsoft Windows Storage Spaces Controller
CVE-2026-68877 is a heap-based buffer overflow (CWE-122) in the Windows Storage Spaces Controller component of Microsoft Windows. The flaw is triggered locally by an authorized attacker: the CVSS vector (AV:L/AC:L/PR:L/UI:N) indicates the attacker needs only low privileges, local access, and no user interaction. A successful exploit yields high impact across confidentiality, integrity, and availability, meaning the attacker gains local code execution on the affected host. Potentially affected are Windows systems shipping the Storage Spaces Controller component; the provided data does not specify exact affected versions, so defenders should check Microsoft's advisory for the precise affected ranges. Exploitation status is currently quiet: no public proof of concept is known, the CVE is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (16th percentile).
What to do: No fixed versions were provided in the available data, so track Microsoft's advisory and apply the corrective update via Windows Update/WSUS as soon as it is released, prioritizing Windows Server hosts that use Storage Spaces or Storage Spaces Direct. In the interim, tighten local access — remove or constrain standard-user accounts on Windows hosts — because exploitation requires an authorized local attacker. Monitor hosts running the Storage Spaces controller for anomalous process or privilege activity, noting that no public PoC or in-the-wild exploitation is currently known.
| Microsoft Windows (Storage Spaces Controller component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.