Impact
A heap-based buffer overflow exists within the Windows NTFS file system, permitting an attacker who already has authorized local access to execute a privilege escalation on the affected machine. The flaw arises when a crafted data condition corrupts a heap buffer during NTFS processing, allowing the attacker to gain higher privileges without needing administrative credentials.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). The vulnerability applies to the listed operating system builds and their corresponding architecture releases.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to trigger the NTFS buffer overwrite, implying that an attacker must be able to introduce malicious metadata or files. Because the attack vector is local and the attacker needs some level of authorization, the risk is centered on privileged escalation within the compromised environment.
OpenCVE Enrichment