Impact
A heap‑based buffer overflow exists in the Windows Volume Manager Extension Driver. This flaw, identified as CWE‑122 and coupled with an out‑of‑bounds read (CWE‑125), allows an unauthorized attacker to inject malicious data that leads to arbitrary code execution with system privileges. Successful exploitation would provide the attacker with full control over the affected machine, enabling further lateral movement, data exfiltration, or persistence mechanisms.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all core installations. The Volume Manager Extension Driver is present on all listed operating systems, making them susceptible to this bug.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity issue, while the EPSS score is currently unavailable, suggesting limited publicly known exploitation activity. The flaw is not listed in CISA’s KEV catalog. The attack likely originates from a malicious network packet targeting the driver’s transport interface; an authenticated or unauthenticated attacker could trigger the overflow by sending crafted data. Since the driver runs in kernel mode, a successful exploit results in elevated privileges and full system compromise. Until a vendor patch is released, the risk remains significant for exposed or unsegmented network environments.
OpenCVE Enrichment