Microsoft Storport.sys Driver Privilege Escalation Vulnerability

Vulnerability

A buffer over-read vulnerability has been identified in the Storport.sys driver, allowing an authorized attacker to locally elevate privileges. This vulnerability affects multiple Windows operating systems, including various versions of Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.

Remediation

Users can apply the security update KB5066835 for Windows 11, KB5066836 for Windows Server 2016 and 2022, and KB5066791 for Windows 10. For Windows Server 2019, the security update is KB5066586.

Added: Oct 14, 2025, 7:05 PM
Updated: Oct 14, 2025, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.