Impact
The vulnerability arises from improper link resolution before file access in the Windows NTFS file system. When an attacker with an authorized account creates or manipulates reparse points or other link mechanisms, the operating system fails to properly restrict operations within a safe directory context. This flaw enables the attacker to gain elevated privileges locally on the affected system, effectively bypassing normal security controls and potentially executing arbitrary code as a privileged user.
Affected Systems
Microsoft Windows 11 versions 23H2 through 26H1 and Microsoft Windows Server 2025 (including Server Core installation) are affected. The flaw is present on both arm64 and x64 architectures for Windows 11, but only on x64 for Windows Server 2025. Systems running any of these product versions without the subsequent update may be vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate‑to‑high severity, and the EPSS score is < 1%, indicating a low probability of exploitation. The flaw is not listed in CISA’s KEV catalogue. Based on the description, a local attacker who already has authenticated access is required to exploit it. The low EPSS suggests the vulnerability has not yet been widely exploited but still warrants prompt remediation.
OpenCVE Enrichment