Home
HIGH: 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
2.1.25156 and lower
affected
Description
Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.
Product status
2.1.25156 and lower
Credits
Tay Kiat Loong
References
www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-043
github.com/winfsp/winfsp/releases/tag/v2.2B1