CVE-2026-72946
massHeap Buffer Overflow in Microsoft Windows Storage Port Driver (LPE)
CVE-2026-72946 is a heap-based buffer overflow (CWE-122) in Microsoft's Storage Port Driver, the in-box Windows driver that handles storage requests. A local attacker who is already authorized on the system can trigger the overflow without user interaction, corrupting heap memory in the driver. Successful exploitation yields local privilege elevation: an attacker with a low-privileged foothold can gain elevated (kernel-level) privileges, with high impact on confidentiality, integrity, and availability of the host. Any system running an affected version of the Windows Storage Port Driver is exposed to this risk from its local users, though the affected version ranges are not enumerated in the available data. There is currently no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-72946 via Windows Update or your patch-management system when available, and verify your installed builds against the affected-version list in Microsoft's advisory. Because exploitation requires an authorized local account but no user interaction, prioritize hosts where untrusted or multiple users can run code, such as RDS/session servers, shared workstations, kiosks, and admin jump boxes. Until patched, restrict local logon and code-execution rights on high-value systems to trusted users.
| Microsoft Windows Storage Port Driver (storport.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.