Impact
The vulnerability is a heap‑based buffer overflow that can be triggered when the operating system processes certain file‑system structures in ReFS, but the official description indicates that the flaw arises in the NTFS subsystem. An attacker who can physically reach the target machine can construct a malicious file system image or otherwise manipulate low‑level structures, causing the overflow and potentially allowing the execution of arbitrary code with system authority. The flaw is categorized as CWE‑122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025 including Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while an EPSS score of < 1% reflects a very low likelihood that the vulnerability will be exploited in the wild. It is not listed in the CISA KEV catalog, further suggesting limited current exploitation activity. The attack vector is inferred to be physical, requiring direct access to the affected devices to craft the exploit payload and trigger the overflow. If successful, privilege escalation would grant the attacker full control over the compromised system.
OpenCVE Enrichment