Impact
A heap-based buffer overflow exists in the Windows NTFS file system, allowing an authorized local user to elevate privileges.
Affected Systems
The flaw affects Microsoft Windows platforms, specifically Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, covering both core and non‑core installations across x86, x64, and ARM architectures.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity due to the potential for local privilege escalation. Exploitation requires local authorization, reducing the likelihood of widespread attacks; the EPSS score of less than 1 % confirms a currently very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, privileged attackers who are able to execute code on the target system remain a serious threat, and the high impact combined with the local attack vector makes patching and monitoring essential.
OpenCVE Enrichment