PT-2026-95433 · Winfsp · Winfsp

·

CVE-2026-93689

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WinFsp versions prior to 2.2.26216
Description A null pointer dereference occurs in the kernel driver's Fast I/O device control handler due to a failure to validate the volume context before use. An unprivileged local user can cause a system crash and denial of service by opening the WinFsp control device and issuing FSP IOCTL TRANSACT requests.
Recommendations Update WinFsp to version 2.2.26216 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93689

Affected Products

Winfsp