PT-2026-95433 · Winfsp · Winfsp
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WinFsp versions prior to 2.2.26216
Description
A null pointer dereference occurs in the kernel driver's Fast I/O device control handler due to a failure to validate the volume context before use. An unprivileged local user can cause a system crash and denial of service by opening the WinFsp control device and issuing
FSP IOCTL TRANSACT requests.Recommendations
Update WinFsp to version 2.2.26216 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winfsp