securitylab_nJuly 15, 2026🇷🇺Translated from Russian

WinFsp Vulnerability CVE-2026-3006 Allows Local Attackers to Escalate Privileges to SYSTEM via Race Condition in Kernel Driver

A seemingly minor flaw in WinFsp can grant a local attacker complete control over a Windows computer by escalating privileges all the way to the SYSTEM account. The platform, widely used to mount virtual disks, network storage, and non-standard file systems, contains components that run with high privileges inside the Windows kernel. Researchers found that these components can be abused through a race condition, turning an ordinary user or compromised process into a full system owner.

Technical Details of CVE-2026-3006

The vulnerability, assigned identifier CVE-2026-3006 and rated 7.0 on the CVSS 3.1 scale, impacts WinFsp 2.1.25156 and all prior versions. It stems from a classic time-of-check-to-time-of-use race condition: when multiple operations access the same resource simultaneously, the driver may process them in an unexpected order. An attacker who times the operations correctly can trigger a memory overflow inside the kernel driver, corrupting a controllable memory region and ultimately executing arbitrary code with SYSTEM rights.

Because the flaw resides in kernel-mode code, the consequences are severe. After gaining SYSTEM privileges the attacker can alter protected system files, install new services and drivers, disable security products, read any local data, and create additional accounts with administrative rights.

Attack Requirements and Scope

The vulnerability cannot be exploited remotely. An attacker must first obtain local execution capability—by running a malicious program, using a compromised user account, or gaining an initial foothold through another vector. Once local access is achieved, the race condition can be triggered to elevate privileges.

The risk extends far beyond users who install WinFsp manually. Many third-party applications that provide file-system virtualization or cloud storage integration ship vulnerable versions of the WinFsp driver. Administrators are therefore advised to audit both standalone WinFsp installations and any bundled copies present on their systems.

Remediation and Recommendations

Developers have already addressed the issue in WinFsp 2.2B1. The Cyber Security Agency of Singapore urges organizations to deploy the updated version immediately. Additional defensive measures include limiting the number of users with local administrative rights and continuously monitoring for unexpected driver or service installations as well as suspicious processes related to WinFsp.

The flaw was discovered by security researcher Tai Kiat Lung. Organizations that rely on WinFsp or any software that depends on it should treat the update as a high priority to prevent local attackers from converting limited access into full system ownership.

Related articles

BoletimSecVulnerabilities & Exploits

Critical Stack Buffer Overflow in TP-Link TL-WR940N Enables Remote Code Execution

A high-severity vulnerability tracked as CVE-2026-12935 with a CVSS score of 8.7 affects the TP-Link TL-WR940N router on hardware version V6. The flaw resides in the RTSP connection tracking module responsible for managing audio and video streaming sessions over the network. It is caused by a stack-based buffer overflow that allows oversized data to corrupt kernel memory, potentially leading to device crashes or full remote code execution. No administrative credentials are required for exploitation, though the attack depends on an RTSP connection initiated by a device already present on the local network. Successful compromise grants attackers the ability to alter router settings, modify DNS servers, intercept traffic, redirect users to malicious sites, and pivot to other connected devices. Users are advised to verify the hardware revision on the device label and apply the region-specific firmware update released by TP-Link.

Security NEXTVulnerabilities & Exploits

N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577

N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.

Security NEXTVulnerabilities & Exploits

Adobe Releases Emergency Update for Campaign Classic Fixing Multiple Critical Vulnerabilities

Adobe has issued an urgent security update for Adobe Campaign Classic to address seven critical vulnerabilities, including several with a maximum CVSSv3.1 base score of 10.0. The flaws affect on-premises deployments on Windows and Linux as well as the on-premises components of hybrid setups. Notably, the newly released fixes also impact the previous emergency update from July 29, version 7.4.3 build 9398, requiring users to apply the latest patch immediately. Among the most severe issues are a server-side request forgery vulnerability tracked as CVE-2026-48331, an input handling flaw in the template engine identified as CVE-2026-48323, and an SQL injection vulnerability labeled CVE-2026-48330. Adobe published the corresponding security advisory on August 3, 2026, urging rapid remediation despite the short interval since the prior update.

SecuritylabVulnerabilities & Exploits

Dark Patterns in Vulnerability Management: How Metrics Undermine Real Security

Vulnerability management programs often fail not due to lack of scanners but because of poorly chosen metrics that prioritize reporting over actual risk reduction. Teams focus on closing easy vulnerabilities, meeting CVSS-based deadlines, and improving dashboard numbers while attackers exploit the shortest path to critical assets. The article examines five common traps including total vulnerability counts, context-free SLAs, closure rate targets, static dashboards, and claims of no critical findings. It argues that these metrics create a false sense of security and distort team behavior according to Goodhart's Law. Instead, organizations should adopt attack path metrics, exposure management approaches such as CTEM, and measurements that track real reduction in attacker reachability. The piece highlights MaxPatrol Carbon as an example of tools that model attacker paths rather than isolated CVEs.