CVE-2026-77492: Windows Storage Port Driver Information Disclosure Vulnerability
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Other sources
Windows Storage Port Driver Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected Windows system and able to perform local actions. The available data does not indicate that it is exploitable remotely or requires user interaction.
What is the potential impact?
Successful exploitation can disclose information through an out-of-bounds read in the Windows Storage Port Driver. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
Which systems are listed as affected?
The affected software list includes Microsoft Windows 10, Windows 11, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.