Impact
An attacker can trigger a heap‑based buffer overflow in the Windows Fast FAT Driver. This flaw allows the execution of arbitrary code with the privileges of the driver, which typically run under the SYSTEM account. The impact is therefore local code execution that can lead to full system compromise, affecting confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local: an unauthorized user or a process with local privileges must trigger the overflow by manipulating the FAT file system structures. Once triggered, the attacker gains the ability to execute code with System privileges, presenting a significant risk to the affected systems.
OpenCVE Enrichment