Impact
An integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. The flaw originates from unchecked arithmetic operations, enabling unintended memory corruption and code execution. The weakness is classified as a buffer overflow (CWE‑122) and arithmetic error (CWE‑190).
Affected Systems
Affected vendors and products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. The documented impact requires physical access to the affected device.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Because a physical attack is required, the threat is confined to environments where an adversary can tamper with the hardware. However, once a physical foothold is achieved, the attacker can execute arbitrary code on the affected system.
OpenCVE Enrichment