ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability

AI summary · glm-5.3

ZDI discloses a Pwn2Own Windows storport integer overflow local privilege escalation flaw (CVE-2026-65814, CVSS 8.8) requiring existing low-privileged code execution.

ZDI advisory ZDI-26-537 describes an integer overflow in the Microsoft Windows storport driver that allows local attackers to escalate privileges. Exploitation requires the attacker to first obtain the ability to execute low-privileged code on the target system. The vulnerability has a CVSS rating of 8.8 and is tracked as CVE-2026-65814; it originated from Pwn2Own.

  • Integer overflow in Windows storport driver enables local privilege escalation
  • Requires prior low-privileged code execution on target
  • CVSS 8.8, assigned CVE-2026-65814, Pwn2Own finding

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65814
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65814.

This source does not provide full text. Read it at zerodayinitiative.com.