CVE-2026-65791

9.8

Microsoft · Windows

A heap-based buffer overflow in the Windows iSCSI Target Service allows unauthenticated, remote attackers to execute arbitrary code.

Executive summary

A critical heap-based buffer overflow in the Windows iSCSI Target Service allows unauthenticated remote attackers to achieve code execution on vulnerable systems.

Vulnerability

This vulnerability is a heap-based buffer overflow within the iSCSI Target Service. An unauthenticated attacker can send specially crafted packets to the service, resulting in memory corruption and arbitrary code execution.

Business impact

The CVSS score of 9.8 highlights the critical risk posed to storage infrastructure. A successful exploit grants an attacker the ability to execute code with elevated privileges, potentially resulting in complete storage unit takeover, data theft, or permanent denial of service for critical applications relying on iSCSI storage.

Remediation

Immediate Action: Update all affected Windows Server and Windows 10 systems to the latest security release from Microsoft immediately.

Proactive Monitoring: Monitor iSCSI traffic for anomalous packet sizes or unusual connection patterns that could indicate overflow attempts.

Compensating Controls: Use network access control lists to restrict iSCSI traffic to known, trusted initiator IP addresses only, reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is a critical vulnerability impacting storage-related services, which are often central to enterprise operations. Patching should be prioritized to prevent remote code execution and potential data integrity issues.

More Microsoft CVEs