Impact
The vulnerability is a heap‑based buffer overflow within the Windows NTFS file system driver. It allows an unauthenticated local attacker to craft a malicious file name, content, or metadata that triggers the overflow during NTFS processing. The resulting code execution is carried out with the privileges of the current user. This flaw falls under CWE‑122 and can compromise confidentiality, integrity, or availability of the affected machine.
Affected Systems
Microsoft Windows 10 operating systems from build 1607 to 22H2, Windows 11 operating systems from build 23H2 to 26H1, and the Windows Server family from Server 2012 (including Server Core installations) through Server 2025 are impacted. The core NTFS driver embedded in these releases contains the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of the same vulnerability is reported as less than 1%, suggesting that exploitation in the wild is presently unlikely. The exploitation requires local access and a crafted file; the vulnerability is not listed in Microsoft’s KEV catalog. If an attacker can influence NTFS processing, the buffer overflow can be leveraged to achieve local code execution.
OpenCVE Enrichment