ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65814.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-537?
The severity of ZDI-26-537 is rated at 8.8 according to CVSS.
How do I fix ZDI-26-537?
To fix ZDI-26-537, ensure that your Microsoft Windows is updated to the latest security patches provided by Microsoft.
What type of vulnerability is ZDI-26-537?
ZDI-26-537 is an integer overflow vulnerability that can lead to local privilege escalation.
Who is affected by ZDI-26-537?
ZDI-26-537 affects installations of Microsoft Windows that have not applied the security updates.
What must an attacker do to exploit ZDI-26-537?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-26-537.