Impact
The vulnerability is a heap‑based buffer overflow in the Windows NTFS file system component. When an attacker manipulates a specially crafted file that the system processes, the overflow can overwrite adjacent heap memory and allow the attacker to execute arbitrary code on the vulnerable machine. This flaw is classified as CWE‑122 and represents a classic memory corruption scenario that compromises confidentiality and integrity for any user who can write or modify the affected files. The attack requires local access because the attacker must create or alter a malicious file on the host
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 24H2, 25H2, 26H1), and Microsoft Windows Server 2012 through 2025, including both standard and Server Core installations. All architectures—x86, x64, and ARM64—are affected, reflecting the ubiquity of the NTFS component across these platforms
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for local code execution, yet the EPSS score of less than 1 % suggests that exploitation in the wild is currently very unlikely, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires local user privileges to create a malicious file, privileged or administrative accounts pose the greatest risk; successful exploitation could lead to privilege escalation or full system compromise. The absence of a known public exploit and the low EPSS reduce the immediacy of the threat relative to the defect’s severity.
OpenCVE Enrichment