Impact
A buffer over‑read occurs within the Windows NTFS file system implementation that allows an attacker with physical access to read beyond the intended data region. The flaw does not enable arbitrary code execution; instead it can expose bytes that were previously not exposed, potentially revealing sensitive information from other files or system structures. The disclosure is limited to the data accessible via the vulnerable read operation, and no broader compromise of system integrity or availability follows from the vulnerability alone.
Affected Systems
The vulnerability affects multiple Microsoft Windows OS releases, including Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 to 26H1, and Windows Server editions from 2012 to 2025. All supported architectures (x86, x64, ARM64) are listed as affected, covering both desktop and server core installations.
Risk and Exploitability
The CVSS score of 4.6 reflects a moderate risk level, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the broader population. The vulnerability is not catalogued in CISA’s KEV list. Exploitation requires physical access or direct interaction with the system’s underlying storage media, which limits the attack surface; remote attackers would have to gain physical access to exploit this issue.
OpenCVE Enrichment