Impact
The flaw is an incorrect authorization check in the Windows Container Isolation FS Filter Driver (unionfs.sys). Because the driver fails to verify permissions properly, an attacker who already has local access can read data that should be protected by the container isolation boundaries. This results in a confidentiality compromise but does not lead to denial of service or remote code execution. The weakness is an Authorization Control problem, identified as CWE-863.
Affected Systems
Microsoft Windows 11, version 26H1 running on x64 hardware. The vulnerability resides in the unionfs.sys driver that implements filesystem isolation for Windows containers.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity, and the EPSS score is less than 1%, suggesting a very low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. Attacking the flaw requires a local, authorized presence, such as a user with administrative rights on the host or container. The attack vector is therefore limited to local privilege escalation or exploitation of existing local privileges; no remote exploitation is described.
OpenCVE Enrichment