Impact
An out‑of‑bounds read in the Windows NTFS file system allows an authorized local attacker to read data beyond the intended boundaries, potentially exposing information stored on the disk. The flaw is identified as CWE‑125, indicating missing bounds checking before performing a read operation. The description indicates that the disclosure is limited to local, authorized users and does not mention remote exploitation or further compromise.
Affected Systems
The vulnerability affects Microsoft Windows operating systems listed in the CNA vendor/product notes, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2016, 2019, 2022, and 2025, with both full and Server Core installations. All supported architectures (x86, x64, ARM64) for these releases are vulnerable as described.
Risk and Exploitability
The CVSS score of 5.5 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation. Exploitation requires local authorized access, and remote attackers are not able to leverage the flaw without first gaining user-level control.
OpenCVE Enrichment