Impact
The vulnerability is a heap‑based buffer overflow in the Windows NTFS file system driver. When triggered by privileged user actions—such as creating or modifying certain files—a flaw allows an attacker with local user rights to write data beyond the bounds of a buffer. Successful exploitation grants elevated privileges on the host, enabling the attacker to execute arbitrary code or modify system files. The weakness is a classic heap overflow identified as CWE‑122.
Affected Systems
This issue pertains to Microsoft Windows operating systems, including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. All listed releases are affected by the NTFS heap overflow.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. An exploit requires local access and an authorized user, so the attack vector is local, not remote. Because the EPSS score is not provided, we cannot quantify current exploitation probability, but the absence from CISA’s KEV catalog suggests that widespread attacks are not yet reported. Nevertheless, security teams should treat this as a potential local privilege escalation vector that could be used to bypass system controls and assume administrator rights.
OpenCVE Enrichment