Impact
The vulnerability is a buffer over-read in the Windows Projected File System Filter Driver. An authorized local user can exploit this flaw to read memory beyond intended bounds, which can trigger privilege escalation. The attacker can execute code or gain higher privileges on the affected machine, allowing access to confidential data or system control.
Affected Systems
Affected systems are Microsoft Windows 10 versions 1809 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server editions 2019, 2022, and 2025 (including core installations). The Projected File System component across these releases is impacted as identified by the CNA vendor list.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, but EPSS is not available, so the precise exploitation probability is unknown. It is not listed in the CISA KEV catalog, meaning no widespread public exploitation is reported yet. Because the flaw requires local authorization, threat actors that can log in as a user or compromise a local account can use the over-read to elevate privileges, potentially affecting confidentiality, integrity, and availability of the compromised system.
OpenCVE Enrichment