Impact
A heap-based buffer overflow exists in the Windows CD-ROM driver, allowing an attacker who is already authenticated on the affected operating systems to gain elevated local privileges. Based on the description, it is inferred that the overflow occurs when the driver processes input constructed by the attacker, enabling the attacker to execute code with higher authority and potentially compromise system integrity. The weakness is classified as CWE-122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, both full and server core installations. The vulnerability is present across 32‑ and 64‑bit architectures and includes ARM64 systems running newer Windows 11 builds.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local authorization, a privileged user or user with elevated group membership could exploit it; remote exploitation is not supported by the provided description.
OpenCVE Enrichment