Impact
An integer overflow or wraparound flaw exists in Windows NTFS that permits an authorized local attacker to elevate privileges. This escalation allows the attacker to gain higher authority within the system without needing additional credentials. The attacker may execute arbitrary code with elevated rights, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability affects Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. All listed architectures of these products are impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity for local privilege escalation. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. The likely attack vector requires local, authorized access; remote exploitation is not supported. Due to the potential for local users to gain administrative rights, the risk is moderate but the impact if exploited is significant.
OpenCVE Enrichment