CVE-2026-35415: Windows Storage Spaces Controller Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
Other sources
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9140Patch KB5087537 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2113Patch KB5089548 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23181Patch KB5087471 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8457Fixed in 10.0.26100.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7079Patch KB5087420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8457Fixed in 10.0.26200.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7291Patch KB5087544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35415?
CVE-2026-35415 has a high severity as it allows an authorized attacker to elevate privileges locally on affected systems.
How do I fix CVE-2026-35415?
To fix CVE-2026-35415, apply the latest security patches provided by Microsoft for the affected products.
Which systems are affected by CVE-2026-35415?
CVE-2026-35415 affects several Microsoft products, including Windows Server 2012 R2, Windows 10, Windows 11, and Windows Server 2022.
Can CVE-2026-35415 be exploited remotely?
No, CVE-2026-35415 requires local access to exploit the vulnerability as it is an elevation of privilege issue.
What is the nature of the vulnerability in CVE-2026-35415?
CVE-2026-35415 is caused by an integer overflow or wraparound in the Windows Storage Spaces Controller.