Impact
An out‑of‑bounds read flaw exists in the Windows NTFS subsystem that allows an attacker with local authorized access to read data beyond the intended memory bounds. The vulnerability can expose sensitive files, configuration data, or credentials stored on the target system. The weakness aligns with CWE‑125, an out‑of‑bounds read error.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% points to a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and exploitation requires local privileged access, making it a local attack vector.
OpenCVE Enrichment