Impact
The vulnerability is a heap‑based buffer overflow in the Windows NTFS file system driver. An authenticated local user can supply specially crafted data that corrupts internal buffers while the NTFS driver processes the file system, leading to arbitrary code execution with the privileges of the logging‑in account. The flaw is identified as CWE‑122 and enables local code execution, which can be leveraged for privilege escalation or data compromise.
Affected Systems
Affected Windows operating systems include Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server 2012 through 2025, covering x86, x64, and ARM64 builds as well as Core installations.
Risk and Exploitability
The CVSS base score of 7.3 indicates high severity. The EPSS score of less than 1% shows a low likelihood of public exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is local, requiring the attacker to have legitimate user access. Successful exploitation would allow code execution in the context of the compromised account, potentially leading to privilege escalation or data compromise.
OpenCVE Enrichment