Impact
An out-of-bounds read in the NTFS file system driver allows an authenticated local attacker to read memory beyond a buffer and consequently elevate their privileges. The flaw is a classic memory corruption vulnerability, classified as CWE‑125, and can be used to increase a user’s integrity level on the affected Windows system.
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 24H2, 25H2, 26H1, and all Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
With a CVSS score of 7.8 this is considered a high‑severity local privilege escalation. The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV database, indicating a low likelihood of widespread exploitation. The attack vector is strictly local; an adversary must have existing local user access to trigger the read operation. Successful exploitation enables the attacker to obtain administrative or system‑level privileges on the target machine.
OpenCVE Enrichment