Impact
A heap‑based buffer overflow exists in the NTFS file system component of Windows, permitting an authorized attacker to execute arbitrary code with the privileges of the local process. The weakness is identified as CWE‑122 and can lead to full control of the affected system if successfully triggered.
Affected Systems
Microsoft Windows operating systems are affected, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and all major Windows Server releases from 2012 to 2025, covering both standard and Server Core installations. Both 32‑bit and 64‑bit builds are impacted as indicated by the CPE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for systems that can be accessed locally by an attacker. The EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack requires a locally authorized user to trigger the heap overflow.
OpenCVE Enrichment