CVE-2026-68844: Windows Storage Spaces Controller Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
Other sources
Windows Storage Spaces Controller Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must already be authorized on the affected system and can exploit the vulnerability locally. The provided severity vector indicates low privileges are required and no user interaction is needed.
What impact could successful exploitation have?
Successful exploitation can allow code execution and is rated as having high impact on confidentiality, integrity, and availability. This could enable an attacker to access data, alter data, or disrupt the affected system.
Which systems are identified as affected?
The listed affected products are Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.