Impact
This vulnerability is a heap‑based buffer overflow in the Windows NTFS file system driver (CWE‑122). The flaw allows an attacker to craft a malicious NTFS object that overflows a heap buffer when the driver copies data, corrupting control data and enabling the execution of arbitrary code. The code would run with the privileges of the NTFS context, resulting in local code execution on the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2012 (standard and Server Core); Windows Server 2012 R2 (standard and Server Core); Windows Server 2016; Windows Server 2019 (standard and Server Core); Windows Server 2022; and Windows Server 2025 (standard and Server Core).
Risk and Exploitability
The CVSS v3.1 score is 8.4, indicating a high severity, while the EPSS score of less than 1% shows a very low but nonzero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying a malicious NTFS file locally or on a shared volume; when the system processes the file, the overflow occurs and arbitrary code is executed with local privileges.
OpenCVE Enrichment