Impact
A heap-based buffer overflow exists in the Windows LUAFV (LUA File Virtualization Filter) driver. The overflow can be triggered by an authorized local user and leads to privilege escalation on the affected system. This flaw is identified as CWE-122, indicating a buffer overflow weakness that allows attackers to overwrite arbitrary memory locations.
Affected Systems
The vulnerability affects several Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2 through 26H1 and 25H2; and Windows Server releases from 2012 through 2025. Both standard and core installations of these Server editions are impacted.
Risk and Exploitability
The CVSS score of 7 signals a moderate level of severity, though no EPSS information is available and the issue is not listed in CISA KEV. Because the attack requires local, authorized access, it does not involve remote exploitation, but an attacker with local privileges could gain system or administrative rights. The lack of documented exploitation does not diminish the potential impact to confidentiality, integrity, or availability on the affected machines.
OpenCVE Enrichment