Winfsp
by Winfsp
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-3006 | Hig | 0.46 | 7.0 | 0.00 | Apr 27, 2026 | Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software. | ||
| CVE-2026-93689 | Med | 0.29 | 5.5 | 0.00 | Sep 18, 2026 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device… | ||
| CVE-2026-7162 | Hig | 0.00 | 7.8 | 0.00 | Jul 13, 2026 | Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software. |
- risk 0.46cvss 7.0epss 0.00
Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.
- risk 0.29cvss 5.5epss 0.00
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device…
- risk 0.00cvss 7.8epss 0.00
Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.