Impact
A heap‑based buffer overflow exists in the Windows Universal Disc Format File System Driver (UDFS). This flaw permits an unauthorized attacker to inject and execute arbitrary code when a malicious media image is processed by the driver. The vulnerability is mapped to CWE‑122 (Heap Buffer Overflow) and CWE‑190 (Integer Overflow or Wraparound). The primary impact is the ability to run code with the privileges of the system process, potentially compromising confidentiality, integrity, and availability of the affected computer.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 including their Server Core and standard editions. The flaw affects the native UDFS driver integrated into these operating systems, which is used to read ISO‑9660 or UDF file system removable media.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity, while the EPSS score of less than 1% signals a very low probability of exploitation at the time of this analysis. The flaw is not listed in the CISA KEV catalog, suggesting fewer publicly documented exploits. The attack vector is inferred to be a physical attack that involves supplying a specially crafted UDF image to the target system. Successful exploitation would allow the attacker to run code with elevated privileges, potentially leading to full system compromise. Given the medium severity and low exploitation probability, the risk is considered moderate, but organizations should address the issue promptly to mitigate potential future exploitation.
OpenCVE Enrichment