Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-34332

Опубликовано: 12 мая 2026
Источник: msrc
CVSS3: 8
EPSS Низкий

Описание

Windows Kernel-Mode Driver Remote Code Execution Vulnerability

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

FAQ

According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are low (PR:L). What does that mean for this vulnerability?

Exploitation of this vulnerability requires an authorized attacker on the domain to wait for a user to initiate a connection to a malicious server that the attacker has set up prior to the user connecting.

How could an attacker exploit the vulnerability?

An attacker could exploit this vulnerability by sending a specially crafted NVMe over Fabrics (NVMe‑oF) response message during the connection handshake process that contains an invalid header length value.

Обновления

ПродуктСтатьяОбновление
Windows Server 2025
Windows Server 2025 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 41%
0.00511
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
3 месяца назад

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

CVSS3: 8
github
3 месяца назад

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

CVSS3: 8
fstec
3 месяца назад

Уязвимость драйвера Kernel-Mode Driver операционных систем Windows, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00511
Низкий

8 High

CVSS3