Impact
The vulnerability resides in the Windows Universal Disk Format File System (UDFS) driver. It permits elevation of privilege, allowing an attacker to execute code with higher system privileges. The weakness is characterized by a buffer under-read (CWE-125) and a signed integer overflow (CWE-191), which can corrupt internal driver state when handling a malicious UDFS image.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the flaw is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector is local, where a malicious UDFS image is presented to or accessed by the affected operating system, allowing the attacker to trigger the driver flaw and gain system privileges.
OpenCVE Enrichment