Impact
A buffer over-read occurs within the NTFS file system, allowing an attacker to read beyond the intended memory boundaries and disclose data that should remain hidden. This vulnerability leads to local information disclosure and is classified under CWE-126.
Affected Systems
The flaw affects multiple Windows operating releases, including Windows 10 (versions 1607 through 22H2) and Windows 11 (versions 23H2 through 26H1), as well as Windows Server editions from 2012 up to 2025, in both standard and Server Core configurations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and no EPSS score is available. The vulnerability is not listed in CISA’s KEV catalog, but it still requires an attacker with local system privileges or an authorized user context to trigger the buffer over-read. Successful exploitation would result in the exposure of sensitive data residing on the local file system.
OpenCVE Enrichment