CVE-2026-69575
massUse-After-Free Local Privilege Escalation in Windows Storage Spaces Controller
CVE-2026-69575 is a use-after-free memory-safety flaw (CWE-416) in the Windows Storage Spaces Controller, the component that manages Storage Spaces virtual disks on Windows. A local attacker who already holds a valid low-privileged account can trigger the flaw, though the CVSS attack-complexity rating of high suggests reliable exploitation requires specific timing or system conditions. Successful exploitation elevates the attacker's privileges on the local machine, granting administrative-level ability to read and modify data and to disrupt the system. Any Windows edition that ships the Storage Spaces Controller is affected, with practical risk concentrated on hosts where multiple or untrusted users can sign in locally. Exploitation status is currently quiet: no public proof-of-concept, no CISA KEV listing, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.
What to do: Apply the Microsoft security update addressing CVE-2026-69575 on all supported Windows clients and servers via Windows Update/WSUS when released, prioritizing multi-user servers and hosts running Storage Spaces or Storage Spaces Direct. Until patching is complete, restrict local interactive and RDP logon rights to trusted accounts, since exploitation requires an authorized local session. After deploying the update, verify the patched Storage Spaces component is present on storage-heavy servers.
| Microsoft Windows Storage Spaces Controller (Windows client and server editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.