Impact
The Windows Universal Disk Format (UDFS) file system driver contains an elevation‑of‑privilege flaw that could allow an attacker who can interact with the driver to gain higher privileges on the local system. The vulnerability could compromise confidentiality, integrity and availability by enabling the attacker to run code with system‑level permissions. The exact exploitation scenario is not detailed in the available description, but the impact is clear.
Affected Systems
Affected by this flaw are multiple Microsoft Windows and Server releases, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 22H3, 26H1, and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 and their Server‑Core variants.
Risk and Exploitability
Based on the CVSS score of 7.8 the vulnerability is rated as high severity. The EPSS score of <1 % indicates it is currently unlikely to be widely exploited. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to gain access to the UDFS driver interface, which typically requires local presence, suggesting the risk is mainly from local attackers or compromised devices.
OpenCVE Enrichment