Impact
This vulnerability is a heap-based buffer overflow (CWE‑122) in the Windows Volume Manager Extension Driver. An attacker who can send specially crafted network traffic to the driver can cause the driver to write beyond the bounds of a buffer allocated on the heap. The overflow can be exploited to execute arbitrary code with the same privileges as the driver, which typically runs in a high‑privilege context. Because the vulnerability is triggered remotely through network traffic, an attacker does not require local access or privileged user credentials on the target machine.
Affected Systems
Affected systems include a broad range of Microsoft Windows operating systems: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, both full and Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. No EPSS data is currently available, so the expected exploitation likelihood is unknown, and the vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is remote network traffic targeting the Volume Manager Extension Driver. If exploitation succeeds a malicious actor could gain system-level privileges on the affected machine, compromising confidentiality, integrity, and availability of the host and any network resources it connects to.
OpenCVE Enrichment