Impact
An over‑read of a memory buffer in the Windows Redirected Drive Buffering component allows a user with legitimate local access to gain higher privileges on the affected system. The vulnerability arises from improper bounds checking, identified as a buffer over‑read (CWE-122/126). This flaw can be exploited to elevate a local user to an account with administrative rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2012 through Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The vulnerability requires local authorized access; no remote trigger is documented, so the attack surface is limited to users already logged on to the system. If the vulnerability is exploited, the attacker gains higher privileges, which could enable them to perform actions that require administrative rights. The CVE description does not specify the exact extent of potential damage beyond privilege escalation, so any further impacts are inferred.
OpenCVE Enrichment