Microsoft published security updates for several Windows elevation of privilege vulnerabilities affecting core components, including Windows Storage Spaces Controller, Windows SMB Client, and Windows Speech Runtime. The issues were tracked as CVE-2026-27907, CVE-2025-32718, and CVE-2025-58715, respectively, and all could allow attackers to gain higher privileges on affected systems after initial access.
Among the disclosed flaws, Microsoft provided the most detail for CVE-2026-27907, describing it as an integer underflow issue (CWE-191) in Windows Storage Spaces Controller that could let a locally authenticated low-privileged attacker elevate privileges to SYSTEM without user interaction. Microsoft rated that vulnerability Important with a CVSS 3.1 score of 7.8, said it was not publicly disclosed or exploited at publication, assessed exploitation as less likely, and released an official fix as part of its security guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-27907, an Important Windows Storage Spaces Controller elevation of privilege flaw caused by an integer underflow that could let a locally authenticated low-privilege attacker gain SYSTEM privileges without user interaction. Microsoft said the vulnerability was neither publicly disclosed nor exploited at publication and that a fix was available.
Microsoft published a Security Update Guide entry for CVE-2025-58715, an elevation of privilege vulnerability affecting Windows Speech Runtime, indicating the issue was formally disclosed through its update guidance.
Microsoft published a Security Update Guide entry for CVE-2025-32718, an elevation of privilege vulnerability affecting the Windows SMB Client, indicating an official security update was available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.