WinFsp Vulnerability CVE-2026-3006 Allows Local Attackers to Escalate Privileges to SYSTEM via Race Condition in Kernel Driver
A seemingly minor flaw in WinFsp can grant a local attacker complete control over a Windows computer by escalating privileges all the way to the SYSTEM account. The platform, widely used to mount virtual disks, network storage, and non-standard file systems, contains components that run with high privileges inside the Windows kernel. Researchers found that these components can be abused through a race condition, turning an ordinary user or compromised process into a full system owner.
Technical Details of CVE-2026-3006
The vulnerability, assigned identifier CVE-2026-3006 and rated 7.0 on the CVSS 3.1 scale, impacts WinFsp 2.1.25156 and all prior versions. It stems from a classic time-of-check-to-time-of-use race condition: when multiple operations access the same resource simultaneously, the driver may process them in an unexpected order. An attacker who times the operations correctly can trigger a memory overflow inside the kernel driver, corrupting a controllable memory region and ultimately executing arbitrary code with SYSTEM rights.
Because the flaw resides in kernel-mode code, the consequences are severe. After gaining SYSTEM privileges the attacker can alter protected system files, install new services and drivers, disable security products, read any local data, and create additional accounts with administrative rights.
Attack Requirements and Scope
The vulnerability cannot be exploited remotely. An attacker must first obtain local execution capability—by running a malicious program, using a compromised user account, or gaining an initial foothold through another vector. Once local access is achieved, the race condition can be triggered to elevate privileges.
The risk extends far beyond users who install WinFsp manually. Many third-party applications that provide file-system virtualization or cloud storage integration ship vulnerable versions of the WinFsp driver. Administrators are therefore advised to audit both standalone WinFsp installations and any bundled copies present on their systems.
Remediation and Recommendations
Developers have already addressed the issue in WinFsp 2.2B1. The Cyber Security Agency of Singapore urges organizations to deploy the updated version immediately. Additional defensive measures include limiting the number of users with local administrative rights and continuously monitoring for unexpected driver or service installations as well as suspicious processes related to WinFsp.
The flaw was discovered by security researcher Tai Kiat Lung. Organizations that rely on WinFsp or any software that depends on it should treat the update as a high priority to prevent local attackers from converting limited access into full system ownership.
Related articles
Fuzzy Logic in Cybersecurity: Reducing Vulnerability Queue by 7.5 Times with CVSS, EPSS and FSTEC Comparison
An information security specialist has developed a fuzzy logic system that prioritizes vulnerabilities far more effectively than traditional scoring methods. The approach uses linguistic variables and membership functions to handle the inherent uncertainty in exploitability and impact assessments. By integrating EPSS probability data with CVSS impact scores and vulnerability age, the model reduces the actionable backlog by a factor of 7.5. The implementation relies on the Mamdani inference algorithm and trapezoidal membership functions to produce smooth, human-interpretable urgency ratings. Detailed coverage checks and rule-base validation ensure no gaps exist in the decision space. Real-world testing on CVE-2025-49113 in Roundcube Webmail demonstrated practical advantages over rigid threshold logic. The method is positioned as a practical enhancement rather than a replacement for existing standards.
VLC Media Player Hit by Two Memory Corruption Flaws Exploitable via Malicious PNG and Rogue RealRTSP Server
Two vulnerabilities have been discovered in the VLC media player that allow out-of-bounds memory access. The issues affect versions from 3.0.0 through 3.0.23. CVE-2026-56711, rated 8.6 on CVSS 4.0, stems from an integer overflow when calculating image buffer sizes in PNG files, enabling attackers to trigger writes beyond allocated memory simply by opening a crafted image or loading it from a playlist. CVE-2026-73324, scored 6.9, resides in the RealRTSP module and permits a malicious server to send an oversized response string that causes reads past the end of a buffer due to a missing null terminator. Both flaws are present in official VideoLAN builds, although some distributions may exclude the RealRTSP component. No special configuration or plugins are required to trigger the issues. Until patched releases appear, users are advised to avoid opening images or playlists from untrusted sources and to refrain from connecting to unknown RealRTSP streams.
September Windows 11 Security Update KB5124008 Breaks Always On VPN Certificate Authentication
The September security update KB5124008 for Windows 11 has introduced a regression that disables Always On VPN connections using certificate-based authentication. The issue affects devices running Windows 11 versions 24H2 and 25H2 that connect to Remote Routing and Access Service (RRAS) and Network Policy Server (NPS) instances on Windows Server 2019. VPN profiles deployed via Microsoft Intune are impacted, with the failure occurring during the certificate negotiation phase of the IPsec connection. Users confirm the problem is reproducible: the VPN works before the patch, stops after installation, and resumes after patch removal and reboot. Microsoft has not yet acknowledged the regression or released a fix, leaving administrators to pause deployment through WSUS or Intune and open support cases with client and NPS logs. A potential workaround involves switching profiles to EAP-TLS, though its reliability remains unconfirmed.
API Token Lifecycle: From Issuance to Revocation and Secure Management
The article provides a comprehensive examination of the full API token lifecycle in browser-based applications, emphasizing that signatures alone cannot prevent token theft. It details risks introduced at issuance, storage, transmission, and revocation stages, including improper OAuth grant types and long-lived tokens. Key recommendations include short-lived access tokens, atomic refresh token rotation, and the use of Authorization Code Flow with PKCE for public clients. Storage advice strongly discourages localStorage and sessionStorage in favor of HttpOnly cookies or a Backend-for-Frontend pattern that keeps real tokens on the server. The piece also covers CSRF protections, rate limiting on authorization endpoints, and the advantages of signed client assertions over static secrets. Overall, it stresses that token security depends on the entire lifecycle architecture rather than cryptographic strength alone.