Impact
An integer underflow bug in the Windows NTFS file system causes the kernel to read or copy memory beyond bounds, which an attacker could exploit to execute arbitrary code with system privileges. The flaw is classified as CWE‑122 and CWE‑191, indicating a heap‑based buffer overflow and an integer overflow/underflow, respectively. The precise exploitation conditions are not fully disclosed in the provided description, but it is inferred that the attacker would need to manipulate NTFS structures on a local volume. Successful exploitation would result in kernel‑level code execution, enabling full system compromise and privilege escalation.
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 releases 1607, 1809, 21H2, 22H2; Windows 11 releases 24H2, 25H2, 26H1; and Windows Server from 2012 through 2025, covering both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 signals serious severity, while an EPSS score of less than 1% indicates a very low current probability of opportunistic exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation is inferred to require local access to a file on an NTFS volume and the creation of crafted data that triggers the underflow; once executed, the attacker gains kernel‑level privileges.
OpenCVE Enrichment