Impact
The Windows Universal Disk Format (UDFS) file system driver contains a flaw that permits a local attacker to elevate privileges, potentially allowing execution of arbitrary code with SYSTEM level permissions and causing a compromise of confidentiality, integrity, and availability. The weakness involves buffer management and numeric processing, reflected in CWE‑122 and CWE‑197 classifications.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both Core and full installations) are all impacted.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is classified as high risk, though the EPSS score is not available and it is not listed in the CISA KEV catalog. The likely attack vector involves a local user who can access a UDFS volume and craft or place malicious media that triggers the flaw. Successful exploitation would grant the attacker SYSTEM privileges and full control of the target system.
OpenCVE Enrichment