CVE-2026-65791
9.8Microsoft · Windows
A heap-based buffer overflow in the Windows iSCSI Target Service allows unauthenticated, remote attackers to execute arbitrary code.
Executive summary
A critical heap-based buffer overflow in the Windows iSCSI Target Service allows unauthenticated remote attackers to achieve code execution on vulnerable systems.
Vulnerability
This vulnerability is a heap-based buffer overflow within the iSCSI Target Service. An unauthenticated attacker can send specially crafted packets to the service, resulting in memory corruption and arbitrary code execution.
Business impact
The CVSS score of 9.8 highlights the critical risk posed to storage infrastructure. A successful exploit grants an attacker the ability to execute code with elevated privileges, potentially resulting in complete storage unit takeover, data theft, or permanent denial of service for critical applications relying on iSCSI storage.
Remediation
Immediate Action: Update all affected Windows Server and Windows 10 systems to the latest security release from Microsoft immediately.
Proactive Monitoring: Monitor iSCSI traffic for anomalous packet sizes or unusual connection patterns that could indicate overflow attempts.
Compensating Controls: Use network access control lists to restrict iSCSI traffic to known, trusted initiator IP addresses only, reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This is a critical vulnerability impacting storage-related services, which are often central to enterprise operations. Patching should be prioritized to prevent remote code execution and potential data integrity issues.