CVE-2026-69290
massStack Buffer Overflow in Microsoft Windows Storage Spaces Controller Allows Local EoP
CVE-2026-69290 is a stack-based buffer overflow (CWE-121) in the Windows Storage Spaces Controller component of Microsoft Windows. An attacker who already has authorized low-privileged access on a local machine can trigger the overflow without user interaction. Successful exploitation allows the attacker to elevate privileges, gaining high-impact read, write, and availability capabilities on the compromised system. Any Windows installation that includes the Storage Spaces Controller is affected; the available data does not specify affected version ranges. Exploitation status is quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
What to do: Monitor Microsoft's security advisory for CVE-2026-69290 and apply the released Windows security update via Windows Update or your patch-management channel, prioritizing multi-user servers and workstations where untrusted users hold local accounts. Until patched, reduce exposure by restricting local sign-in rights on systems that use Storage Spaces. No public PoC or in-the-wild exploitation is known, so incorporation into the normal patch cycle is a reasonable posture.
| Microsoft Windows Storage Spaces Controller (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.