Impact
The vulnerability is located in the Windows Universal Disk Format (UDFS) file system driver that handles UDF-formatted media. An attacker who can trigger the bug can gain higher privileges on the affected system; this elevation of privilege is inferred from the vulnerability type and the listed CWEs. This flaw is categorized as a buffer overflow (CWE-122) combined with an integer overflow (CWE-191) that can bypass permission checks; the integer overflow detail is inferred from the CWE list, as it is not explicitly stated in the CVE description.
Affected Systems
Affected systems include Microsoft Windows operating systems: Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.3 reflects a high severity, but the EPSS score of less than 1% indicates a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers would need local or direct access to UDF-formatted media or a removable device; this attack vector is inferred from the vulnerability type and the lack of documented network exposure. The elevated privileges could allow local attackers to modify or read protected data or install malware with higher permissions.
OpenCVE Enrichment