Impact
A heap‑based buffer overflow in Windows NTFS can be triggered by an authorized local user to gain higher privileges on the affected system. This flaw allows the attacker to overwrite memory structures during normal NTFS operations, potentially enabling execution of arbitrary code with elevated rights. The impact is confined to the local machine but can lead to full control of that host if the privilege escalation succeeds. The weakness is identified as CWE‑122.
Affected Systems
The vulnerability covers a wide range of Microsoft Windows operating systems. Affected clients include Windows 10 from version 1607 through 22H2 and Windows 11 from 23H2 through 26H1. Server editions affected are Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their core installations.
Risk and Exploitability
With a CVSS score of 7.8 the flaw represents a high‑severity local privilege escalation. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The attack requires local access and an authorized user with the ability to perform specific NTFS operations that trigger the overflow. Once the overflow is achieved, the attacker can run code with elevated privileges, potentially compromising the entire system.
OpenCVE Enrichment