Impact
The flaw is a heap‑based buffer overflow located in the Windows NTFS file system driver, as reported by Microsoft. It can be triggered by an attacker who already has local access and supplies specially crafted data to the NTFS service. When exploited, the overflow permits the attacker to run arbitrary code on the affected system, potentially with the elevated privileges that the NTFS service normally holds. The weakness is categorized as CWE‑122 for heap overflows and CWE‑20 for improper input validation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012, 2016, 2019, 2022, 2025 and their corresponding Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 designates this as a high‑severity issue, yet the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and because it requires local authority, the potential impact is limited to users who are already authenticated to the target machine. The low EPSS suggests that widespread attacks are unlikely, but the high impact warrants prompt remediation.
OpenCVE Enrichment