Impact
A buffer over-read flaw in the NTFS file system component can be triggered by a local user who has authorized access to the system and can cause the operating system to read beyond intended memory boundaries, leading to the disclosure of data that should not normally be accessible. The weakness is categorized as CWE-126, which is a classic buffer over-read vulnerability that typically results in partial information leakage rather than full system compromise.
Affected Systems
The vulnerability affects a wide range of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. All impacted editions use the NTFS file system component where the buffer over-read occurs.
Risk and Exploitability
The CVSS score of 5.5 classifies the vulnerability as medium severity, and the EPSS score of less than 1% indicates a low expected likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must already have authorized access to the affected system to trigger the over-read. No remote access, privilege escalation, or code execution capabilities are afforded by this flaw, so the overall risk is moderate but warrants timely remediation to protect sensitive data.
OpenCVE Enrichment