Impact
This vulnerability is a heap-based buffer overflow in Windows Storage that enables an attacker with local authorization to gain elevated privileges. The flaw can be leveraged to execute code with higher rights, potentially allowing system compromise and full control over the affected machine, thereby threatening confidentiality, integrity, and availability. The weakness is identified as CWE‑122, indicating a typical heap corruption scenario.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 across both arm64 and x64 architectures, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations) are affected. The list is based on the vendor and product entries provided by Microsoft.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is local and requires the attacker to be an authorized user on the system. No exploit conditions beyond local access are specified, so the risk is primarily limited to users who can already log in or have local administrative rights. If such conditions are met, an attacker could potentially raise privileges to full control of the operating system.
OpenCVE Enrichment