CVE-2026-71337: Windows Storage Management Provider Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
Other sources
Windows Storage Management Provider Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows Storage Management Provider
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this vulnerability?
The attacker must already be authorized on the affected Windows system and must exploit it locally. The available data does not indicate that remote exploitation or user interaction is required.
2
What is the likely impact of successful exploitation?
Successful exploitation can elevate the attacker's privileges on the local system. The severity vector indicates high impact to confidentiality, integrity, and availability.