CVE-2021-26441: Microsoft Windows storport Integer Overflow Privilege Escalation Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the storport.sys driver. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26441?
CVE-2021-26441 has a severity rating of important, indicating a potential risk for local privilege escalation.
How do I fix CVE-2021-26441?
To remediate CVE-2021-26441, apply the latest security updates provided by Microsoft for your affected Windows version.
Who is affected by CVE-2021-26441?
CVE-2021-26441 affects local users of various Windows operating systems that allow privilege escalation.
What types of attacks can leverage CVE-2021-26441?
Attackers who gain initial low-privileged access can exploit CVE-2021-26441 to elevate their privileges on the system.
Is there a workaround for CVE-2021-26441 until I can apply the fix?
Currently, there are no known workarounds to mitigate CVE-2021-26441, so applying patches is recommended.