medium · CVSS v3 5.5 · CVSS v4 6.8
CVE-2026-93689
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device contro…
Description
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
Scores
- Severity
- medium
- CVSS v2
- 4.6
- CVSS v3
- 5.5
- CVSS v4
- 6.8
- EPSS
- —