Impact
The flaw is a heap‑based buffer overflow in the Windows Storage component that allows an attacker with local access to elevate privileges. The overflow can be triggered by sending data that causes an internal limit to be exceeded, enabling the attacker to gain administrative rights on the affected machine. This elevation compromises confidentiality, integrity, and availability by permitting the attacker to install malware, modify configuration, or exfiltrate data. The weakness is classified as CWE‑122, reflecting improper handling of untrusted input during memory allocation.
Affected Systems
Affected Microsoft Windows versions include Windows 11 23H2, 24H2, 25H2, 26H1, and the 23H2 arm64 build, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation). These versions are identified for both ARM64 and x64 architectures where applicable.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS value is unavailable, so the current likelihood of exploitation remains uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local; an attacker must already authenticate or otherwise execute code on the target system to exploit the overflow. Precise memory offsets are required, which limits widespread ease of exploitation. Nonetheless, once the overflow is triggered the attacker gains administrative privileges, making the issue critical to remediate as soon as possible.
OpenCVE Enrichment