Untrusted Pointer Dereference in Microsoft Windows and Windows Server - CVE-2026-78451
Published: September 9, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Microsoft Windows SCSI Class System File when performing a physical attack. An attacker with physical access can exploit the vulnerability to elevate privileges.
Successful exploitation could grant SYSTEM privileges.
Affected software
Windows Server
How to mitigate CVE-2026-78451
Windows Server - addressed in versions 2019 10.0.17763.9245, 2022 10.0.20348.5622, 2025 10.0.26100.33438