Impact
A heap‑based buffer overflow exists in the Windows Container Isolation FS Filter Driver (unionfs.sys). An attacker with authorized local access can exploit this overflow to gain higher privileges on the host. The flaw is a classic memory corruption issue classified as CWE‑122, enabling an attacker to bypass normal privilege boundaries.
Affected Systems
The vulnerability affects Microsoft Windows 11 26H1 on x64 systems. The affected component is the unionfs.sys driver used for container isolation within this Windows release.
Risk and Exploitability
The CVSS base score of 7.8 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests that, at the time of analysis, the probability of exploitation is low but not zero. The vulnerability is not listed in CISA KEV, reducing the immediate operational awareness for most organizations. The attack vector is inferred to be local, requiring authentication or the ability to deploy a malicious container or process that interacts with the unionfs.sys component. Once exploited, the attacker can elevate privileges to the host level and potentially compromise other containers or the entire system.
OpenCVE Enrichment