Impact
An over‑read buffer bug in the Windows NTFS file system allows an authorized user to read memory locations beyond the intended data bounds, resulting in the disclosure of confidential information stored in adjacent memory. The vulnerability is a classic instance of CWE‑126, where insufficient bounds checking leads to a local data leak but does not provide execution or privilege escalation capabilities.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2, as well as Windows 11 releases 23H2, 24H2, 25H2, and 26H1, are impacted. Server editions affected include Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, across both full and Server Core installations. The vulnerability applies to both 32‑bit and 64‑bit configurations (x86, x64, ARM64) as reflected in the vendor‑reported products.
Risk and Exploitability
The base CVSS score of 5.5 indicates moderate severity, with the EPSS score of less than 1% suggesting a very low likelihood of current exploitation. The vulnerability is not cataloged in CISA’s KEV list, further indicating a low overall threat level. Exploitation requires the attacker to have local user credentials with read access to the NTFS volume; the bug does not allow remote exploitation or privilege escalation, but any local user with sufficient access can gain unintended information.
OpenCVE Enrichment