Impact
A flaw in the Windows Universal Disk Format File System driver can allow an attacker to elevate privileges on the affected system. The vulnerability arises from a flaw in handling UDFS image files, which can cause the driver to execute code with higher privileges than intended. The weakness is catalogued as CWE‑197, indicating a numerical error that can lead to improper handling of data and subsequent privilege escalation.
Affected Systems
The issue affects a wide range of Microsoft operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and several Windows Server releases from 2012 through 2025, including Server Core installations. All impacted platforms appear in the Microsoft update guide linked in the references.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the vulnerability, but the EPSS score is currently unavailable so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, reducing the immediate threat perception but not eliminating risk. Organizations running the affected systems should treat the flaw as significant and consider it when prioritising security measures.
OpenCVE Enrichment