CVE-2026-93689
5.5 MEDIUMpublic exploit availablePublished 2026-09-18 · Updated 2026-09-22
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-476
Public exploit & PoC references
- https://github.com/winfsp/winfsp
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060
- https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652
- https://github.com/winfsp/winfsp/releases/tag/v2.2B4
All references
- https://github.com/winfsp/winfsp
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73
- https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060
- https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652
- https://github.com/winfsp/winfsp/releases/tag/v2.2B4
- https://www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dereference-via-fast-i-o
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100890
- MEDIUMCVE-2026-100895PoC
- MEDIUMCVE-2026-102623
- UNSCOREDCVE-2026-102723PoC
- UNSCOREDCVE-2026-102724PoC
- MEDIUMCVE-2026-102808PoC
- MEDIUMCVE-2026-18746PoC
- HIGHCVE-2026-19888
Related by shared AI tags and CWE weakness class. Browse the full archive.