ZeroHour

CVE-2026-69628

mass

Heap Buffer Overflow in Microsoft Windows iSCSI Allows Network Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69628 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows iSCSI implementation. According to the CVSS vector, an attacker who already holds low-privileged (authorized) credentials can trigger the flaw over the network with no user interaction and low attack complexity, likely by sending crafted input to the iSCSI component. Successful exploitation would let the attacker execute code with high impact on confidentiality, integrity, and availability of the affected host. Any Windows system with the affected iSCSI component is in scope, with the most realistic targets being hosts that use iSCSI initiator/target functionality, such as servers connected to SAN storage. Exploitation has not been confirmed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.9% (58th percentile).

What to do: Apply the Microsoft security update that fixes CVE-2026-69628 as soon as it is available, prioritizing servers and workstations that use the iSCSI initiator to reach SAN storage. As an interim measure, disable the Microsoft iSCSI Initiator service or restrict network access to it on hosts that do not use iSCSI. Given that exploitation requires low-privileged credentials, review which accounts have network access to iSCSI-enabled hosts and harden them to least privilege.

Affected
Microsoft Windows iSCSI (iSCSI initiator/service)
Estimated exposure
massmillions of Windows hosts (the iSCSI component ships inbox with Windows; realistic exposure is concentrated in enterprise servers using iSCSI storage) — The vulnerable iSCSI code is present in the Windows installed base of roughly a billion devices, but exploitation plausibly requires hosts actually running iSCSI connectivity, which public deployment patterns suggest is concentrated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.