Skip to content
Auto-CTI
Back to today
NEW MEDIUM B2

ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability

B ZDI: Published Advisories · · CVE-2026-65814

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.8
EPSS
0%

Affected versions

windows 10 1607 windows 10 1809 windows 10 21h2

Key insight

The vulnerability was demonstrated at Pwn2Own, indicating an available exploit; a local attacker with low privileges can gain system privileges.

Description

The vulnerability CVE-2026-65814 affects the storport driver in Microsoft Windows. An integer overflow allows a local attacker who can already execute low-privileged code to escalate to system privileges. ZDI has assigned a CVSS rating of 8.8. The vulnerability was demonstrated at the Pwn2Own competition. Microsoft Windows installations are affected; the advisory does not provide patch information.

Risk score

56
cvss base
78.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
93.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
31.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

1 TTP
Recon
Resource Dev
Initial Access
Execution
Persistence
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1068
Exploitation for Privilege Escalation
Privilege Escalation After obtaining low-privileged code execution on the target Windows system, the attacker exploits an integer overflow vulnerability in the storport driver to escalate privileges to SYSTEM or higher integrity level. high llm
ESC