ZeroHour

CVE-2026-71337

mass

Elevation of Privilege via Stack Buffer Overflow in Windows Storage Management Provider

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-71337 is a stack-based buffer overflow (CWE-121; the record also tags CWE-130) in the Windows Storage Management Provider, a component of the Microsoft Windows storage management stack. An authorized, low-privileged local user can trigger the overflow via the provider without any user interaction, and the flaw is scored 7.8 (High) with high impact to confidentiality, integrity, and availability. Successful exploitation allows the attacker to elevate privileges locally and run code with higher privileges on the affected machine. Any Windows installation carrying the affected Storage Management Provider is in scope, though the provided data does not specify affected version ranges. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days, indicating no known exploitation at this time.

What to do: Apply Microsoft's security update for CVE-2026-71337 through Windows Update, WSUS, or Intune as soon as it is available, and verify remediation via your patch-reporting tooling. Prioritize Windows systems where multiple or less-trusted users can log on locally (e.g., RDS hosts and shared servers), since exploitation requires local access; temporarily restricting interactive logon rights on sensitive systems is a reasonable interim measure.

Affected
Microsoft Windows Storage Management Provider (Windows component)
Estimated exposure
mass≈ hundreds of millions of Windows devices (in-box Windows component) — The Storage Management Provider ships in-box with widely deployed Windows client and Server releases, so the estimate is drawn from the overall Windows installed base (roughly a billion-plus active devices), with practical risk…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
Weakness
CWE-121, CWE-130
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.