Impact
The vulnerability is an integer overflow or wraparound in the Windows NTFS file system component. This flaw permits an attacker who already has local access to the target machine to elevate privileges by creating specially crafted files that cause the file system to miscalculate values. The impact is a local escalation of privileges, allowing the attacker to gain higher authority on the system, potentially compromising all data and enabling further attacks. The weakness is documented with CWE-190, indicating an integer manipulation error.
Affected Systems
Affected vendors and products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server releases 2012 through 2025, including the Server Core installations of each edition. All of these operating systems currently have a known issue with NTFS that must be addressed by installing the latest Microsoft security update available via the update guide.
Risk and Exploitability
The CVSS score of 7.8 rates this vulnerability as moderately high severity. EPSS data is not available, so the probability of exploitation in the wild is unclear, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an attacker to have write access to NTFS-managed paths or files on the affected systems. Based on the description, it is inferred that the attacker can trigger the overflow by creating or modifying a file that the system processes incorrectly, leading to a privilege increase.
OpenCVE Enrichment