CVE-2026-71337
massElevation of Privilege via Stack Buffer Overflow in Windows Storage Management Provider
CVE-2026-71337 is a stack-based buffer overflow (CWE-121; the record also tags CWE-130) in the Windows Storage Management Provider, a component of the Microsoft Windows storage management stack. An authorized, low-privileged local user can trigger the overflow via the provider without any user interaction, and the flaw is scored 7.8 (High) with high impact to confidentiality, integrity, and availability. Successful exploitation allows the attacker to elevate privileges locally and run code with higher privileges on the affected machine. Any Windows installation carrying the affected Storage Management Provider is in scope, though the provided data does not specify affected version ranges. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days, indicating no known exploitation at this time.
What to do: Apply Microsoft's security update for CVE-2026-71337 through Windows Update, WSUS, or Intune as soon as it is available, and verify remediation via your patch-reporting tooling. Prioritize Windows systems where multiple or less-trusted users can log on locally (e.g., RDS hosts and shared servers), since exploitation requires local access; temporarily restricting interactive logon rights on sensitive systems is a reasonable interim measure.
| Microsoft Windows Storage Management Provider (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
- Weakness
- CWE-121, CWE-130
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.