CVE-2026-93689

Published: Set 18, 2026 Last Modified: Set 22, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,8
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,5
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.

476

NULL Pointer Dereference

Stable
Common Consequences
Security Scopes Affected:
Availability Integrity Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart Execute Unauthorized Code Or Commands Read Memory Modify Memory
Applicable Platforms
Languages: C, C++, Java, C#, Go
View CWE Details
https://github.com/winfsp/winfsp
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060
https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652
https://github.com/winfsp/winfsp/releases/tag/v2.2B4
https://www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dere…