Impact
Heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver allows an authorized local attacker to gain elevated privileges. The vulnerability is an out‑of‑bounds write (CWE-122) that can corrupt heap structures and enable code execution with higher privilege level. Depending on the attacker’s subsequent use of these privileges, it could be used to install software, modify system files, or perform other actions normally prohibited for the compromised identity; these are inferred consequences based on typical high‑privilege capabilities, not directly stated in the description, and may vary with the environment.
Affected Systems
All Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server releases 2016, 2019, 2022, and 2025 (including Server Core installations) are vulnerable. The affected environment spans both client and server platforms, meaning any machine running these OSs without the fix is susceptible.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is considered high severity, but the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread public attacks. Based on the description, it is inferred that the most probable attack vector is a local user with sufficient privileges to load drivers, exploiting the buffer overflow to execute code at elevated privilege. Because the flaw requires local access, remote exploitation is not feasible without additional compromise steps, which is also inferred from the local‑only nature of driver loading described.
OpenCVE Enrichment