Impact
A heap‑based buffer overflow occurs within the Windows NTFS file system implementation, allowing an attacker who can interact with the file system to execute arbitrary code. The weakness is classified under CWE‑122 – an unchecked or insufficient buffer size in a heap allocation. Because the flaw requires a physical interaction with the device to trigger the overflow, the attack vector is limited to a local or physical attacker, but the resulting code executes with the privileges of the NTFS driver, providing high‑level access to the operating system.
Affected Systems
Affected systems include various Windows client and server releases. Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025. All listed editions, whether standard or server‑core installations, suffer from this vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 6.8 indicates a moderate severity, and EPSS data is not available, so exact prevalence cannot be quantified. The weakness is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported at this time. However, for an attacker with physical access, the exploit code is relatively simple to craft and would enable execution of code with the high privileges conferred by the NTFS driver, potentially compromising the entire system.
OpenCVE Enrichment