Impact
The vulnerability is a heap‑based buffer overflow in the Windows NTFS file system. If a local, authorized user exploits it, arbitrary code can be executed with the permissions of the account that performs the NTFS operation, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, in both full and Server Core installations. The vulnerability applies to all supported processor architectures reflected in the reported CPEs.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity, while the EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local deployment by an authenticated user with sufficient NTFS permissions, so the risk is confined to local privilege escalation or compromise of accounts that can perform the vulnerable operation.
OpenCVE Enrichment