PT-2026-7395 · Microsoft · Windows Storage+1
Oscar Zanotti Camp
·
Published
2026-02-10
·
Updated
2026-03-31
·
CVE-2026-21508
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions not specified)
Description
An improper authentication issue in Windows Storage can allow an attacker to elevate privileges locally. The issue involves forcing a system process utilizing the undocumented function
Windows Storage! SHCoCreateInstance to create an arbitrary COM object. This is achieved by manipulating the first argument of a CoCreateInstance call. The vulnerability requires the COM object to be associated with a registered COM class supporting CLSCTX INPROC SERVER.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Authentication
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Storage