Impact
A heap-based buffer overflow in the Windows NTFS file system allows an attacker who can write to an NTFS volume to execute arbitrary code on the local machine. This flaw directly enables local code execution and could be leveraged to elevate privileges or compromise system integrity.
Affected Systems
The vulnerability affects Windows 10 releases 1607, 1809, 21H2, and 22H2, Windows 11 releases 24H2, 25H2, and 26H1, and all recent Windows Server editions from 2012 to 2025, including Server Core installations, as long as default NTFS volumes are in use.
Risk and Exploitability
The CVSS score of 7.8 places it in the high severity category, while an EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector requires local user credentials with NTFS write privileges; based on the description, it is inferred that an attacker would create a malicious metadata structure that triggers the heap overflow.
OpenCVE Enrichment