CVE-2026-93689 PUBLISHED

WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O

Assigner: VulnCheck
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor winfsp
Product winfsp
Versions Default: unaffected
  • affected from 0 to 2.2.26215 (incl.)

Credits

  • Luigino Camastra (AISLE Research)

References

Problem Types

  • NULL Pointer Dereference CWE