Impact
The vulnerability is an out‑of‑bounds read in Windows NTFS that allows a local attacker to corrupt internal data structures and elevate privileges. Documented as CWE‑125, the flaw lets a user with local code execution gain higher access and potentially compromise system integrity.
Affected Systems
Affected systems encompass Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from 23H2 through 26H1, and Windows Server editions from 2012 to 2025, including both full installations and Server Core editions.
Risk and Exploitability
A CVSS score of 7.8 marks the flaw as high severity, and the EPSS score is not available while it is not yet listed in CISA KEV. Because the attacker only needs local authorization, the likely attack vector is inferred to be local. The risk to affected installations remains significant until a patch is applied.
OpenCVE Enrichment