Impact
This vulnerability permits an authorized user to trigger an out‑of‑bounds read within the Windows NTFS file system, which allows local privilege escalation. The flaw is a classic buffer overread that enables an attacker to access memory beyond the intended boundary.
Affected Systems
Affected systems include multiple Microsoft Windows client and server versions. The specific builds listed are Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, covering both Server Core and full installations. These products span both x86 and x64 architectures as well as ARM64 for the newer Windows 11 editions.
Risk and Exploitability
This vulnerability has a CVSS score of 7.8, indicating a high severity local privilege escalation. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time. The attack requires an authenticated user with local access to the affected system; once the issue is triggered the attacker can gain higher privileges on that machine.
OpenCVE Enrichment